Virus ou pas erreur 1058 m.à.jours
Résolu/Fermé
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
-
19 mai 2008 à 17:50
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 - 16 juil. 2008 à 18:06
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 - 16 juil. 2008 à 18:06
Bonjour,
Voici mon problème je ne peux plus accéder à windows update et mes misesà jours sont déactivées. Pour avis j'ai déjà fait SERVICES.MSC (le service ne veux pas se mettre sur automatique ni s'activer pour manuel idem errreur 1058), et regedit, j'a fait aussi par le panneau de config , j'ai tout essayer rien n'y fait. Microsoft ne m'aide en rien. J'ai également telécharger spybot, malwarebytes, ad aware mon ordinateur semble être nettoyer de tout virus et autres du moins je le pense j'ai donc fait un hijackthis et voici ce qu'il me dit , avant merci de m'aider là je sèche complet merci d'avance...
Merci de me dire aussi si pc tools est un bon antivirus j'avais antivir mais il m'a zappé des fichiers importants de mon pc et ça a tout déglingué.... enfin maintenant il ne reste plus que ce problème ci haut.... :)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:39, on 2008-05-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAheadInCDInCDsrv.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesLavasoftAd-Aware 2007aawservice.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesBonjourmDNSResponder.exe
C:WINDOWSsystem32dllhost.exe
C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCDBurnerXPNMSAccessU.exe
C:Program FilesPC Tools AntiVirusPCTAVSvc.exe
C:WINDOWSsystem32PnkBstrA.exe
C:WINDOWSsystem32PnkBstrB.exe
C:Program FilesCyberLinkShared filesRichVideo.exe
C:Program FilesSigmaTelC-Major AudioWDMSTacSV.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32svchost.exe
C:Program FilesWindows Media Connectmswmcls.exe
C:WINDOWSsystem32MsPMSPSv.exe
C:WINDOWSsystem32SearchIndexer.exe
C:WINDOWSsystem32wscntfy.exe
C:WINDOWSsystem32rundll32.exe
C:WINDOWSsttray.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32hkcmd.exe
C:WINDOWSsystem32igfxpers.exe
C:Program FilesJavajre1.6.0_05binjusched.exe
C:Program FilesAheadInCDInCD.exe
C:Program FilesFichiers communsRealUpdate_OBrealsched.exe
C:Program FilesPC Tools AntiVirusPCTAV.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE
C:Program FilesDNAbtdna.exe
C:Program FilesCursorXPCursorXP.exe
C:WINDOWSsystem32rundll32.exe
C:Program FilesWindows Media PlayerWMPNSCFG.exe
C:Program FilesSpybot - Search & DestroyTeaTimer.exe
C:Program FilesLClockLClock.exe
C:Program FilesStardockObjectDockObjectDock.exe
C:WINDOWSsystem32rundll32.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesFichiers communsMicrosoft SharedWindows LiveWLLoginProxy.exe
C:PROGRA~1DVDREG~1DVDRegionFree.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://neufportail.fr/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = https://home.sweetim.com/
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:Program FilesRealRealPlayerrpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:WINDOWSsystem32nnnLcCVl.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:WINDOWSsystem32wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_05binssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesFichiers communsMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesWindows Live Toolbarmsntb.dll
O2 - BHO: (no name) - {DD4A65C7-61D7-445F-BCF1-5065F765EAF9} - C:WINDOWSsystem32urqPgDtR.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:Program FilesEPSONEPSON Web-To-PageEPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:Program FilesEPSONEPSON Web-To-PageEPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesWindows Live Toolbarmsntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar1.dll
O4 - HKLM..Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [Recguard] C:WINDOWSSMINSTRECGUARD.EXE
O4 - HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [Persistence] C:WINDOWSsystem32igfxpers.exe
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_05binjusched.exe"
O4 - HKLM..Run: [InCD] C:Program FilesAheadInCDInCD.exe
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [ISUSPM] "C:Program FileseMuleIncomingCommonInstallShieldUpdateServiceISUSPM.exe" -scheduler
O4 - HKLM..Run: [01234567890123456789012345678901234567890123456789012345678901234567890123456789012345678 901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678 9012345678901234567890123456789012345678901234567890123456789012345678912345678] C:Program Filesuser32.exe
O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [TkBellExe] "C:Program FilesFichiers communsRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [PCTAVApp] "C:Program FilesPC Tools AntiVirusPCTAV.exe" /MONITORSCAN
O4 - HKLM..Run: [BM438aa6a1] Rundll32.exe "C:WINDOWSsystem32qpchvjaa.dll",s
O4 - HKLM..Run: [40b9953d] rundll32.exe "C:WINDOWSsystem32pkccyrou.dll",b
O4 - HKLM..RunServices: [MSys32] "C:Program FilesTetris 3000datamorfitwebentrance.exe"
O4 - HKLM..RunOnce: [Spybot - Search & Destroy] "C:Program FilesSpybot - Search & DestroySpybotSD.exe" /autocheck
O4 - HKLM..RunOnce: [SpybotDeletingA6554] command /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKLM..RunOnce: [SpybotDeletingC8130] cmd /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKLM..RunOnce: [SpybotDeletingA8001] command /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKLM..RunOnce: [SpybotDeletingC7784] cmd /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [NBJ] "C:Program FilesAheadNero BackItUpnbj.exe"
O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - HKCU..Run: [AlertEmail] C:Program FilesAlertEmailalertemail.exe
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [Internet Download Accelerator] C:Program FilesIDAida.exe -autorun
O4 - HKCU..Run: [BitTorrent DNA] "C:Program FilesDNAbtdna.exe"
O4 - HKCU..Run: [CursorXP] C:Program FilesCursorXPCursorXP.exe
O4 - HKCU..Run: [Netlog 24] "C:Program FilesNetlog 24NotifierNetlog24Notifier.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKCU..RunOnce: [SpybotDeletingB5548] command /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKCU..RunOnce: [SpybotDeletingD1483] cmd /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKCU..RunOnce: [SpybotDeletingB9066] command /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKCU..RunOnce: [SpybotDeletingD838] cmd /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:Program FilesLClockLClock.exe
O4 - Startup: ObjectDock.lnk = C:Program FilesStardockObjectDockObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:Program FilesUBISOFTPrince of Persia l'Ame du GuerrierSupportRegisterRegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:Program FilesUberIconUberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:Program Files3Deep Space3D Solar System Screensaverunins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:Program FilesGoogleGoogle UpdaterGoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:Program FilesMicrosoft SQL Server80ToolsBinnsqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:Program FilesWindows Desktop SearchWindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:Program FilesWindows Live Toolbarmsntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_05binssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_05binssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncinetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncinetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncinetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - https://copainsdavant.linternaute.com/
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: urqPgDtR - C:WINDOWSSYSTEM32urqPgDtR.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:Program FilesLavasoftAd-Aware 2007aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:Program FilesFichiers communsMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesFichiers communsInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:Program FilesAheadInCDInCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:Program FilesiPodbiniPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:Program FilesCDBurnerXP Pro 3ToolsNMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:Program FilesCDBurnerXPNMSAccessU.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:Program FilesPC Tools AntiVirusPCTAVSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:WINDOWSsystem32PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:WINDOWSsystem32PnkBstrB.exe
O23 - Service: L Ile Noyee Drivers Auto Removal (pr2ajbeb) (pr2ajbeb) - Micro Application - C:WINDOWSsystem32pr2ajbeb.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared filesRichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:Program FilesSigmaTelC-Major AudioWDMSTacSV.exe
--
End of file - 15919 bytes
merci
Voici mon problème je ne peux plus accéder à windows update et mes misesà jours sont déactivées. Pour avis j'ai déjà fait SERVICES.MSC (le service ne veux pas se mettre sur automatique ni s'activer pour manuel idem errreur 1058), et regedit, j'a fait aussi par le panneau de config , j'ai tout essayer rien n'y fait. Microsoft ne m'aide en rien. J'ai également telécharger spybot, malwarebytes, ad aware mon ordinateur semble être nettoyer de tout virus et autres du moins je le pense j'ai donc fait un hijackthis et voici ce qu'il me dit , avant merci de m'aider là je sèche complet merci d'avance...
Merci de me dire aussi si pc tools est un bon antivirus j'avais antivir mais il m'a zappé des fichiers importants de mon pc et ça a tout déglingué.... enfin maintenant il ne reste plus que ce problème ci haut.... :)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:39, on 2008-05-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAheadInCDInCDsrv.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesLavasoftAd-Aware 2007aawservice.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesBonjourmDNSResponder.exe
C:WINDOWSsystem32dllhost.exe
C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCDBurnerXPNMSAccessU.exe
C:Program FilesPC Tools AntiVirusPCTAVSvc.exe
C:WINDOWSsystem32PnkBstrA.exe
C:WINDOWSsystem32PnkBstrB.exe
C:Program FilesCyberLinkShared filesRichVideo.exe
C:Program FilesSigmaTelC-Major AudioWDMSTacSV.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32svchost.exe
C:Program FilesWindows Media Connectmswmcls.exe
C:WINDOWSsystem32MsPMSPSv.exe
C:WINDOWSsystem32SearchIndexer.exe
C:WINDOWSsystem32wscntfy.exe
C:WINDOWSsystem32rundll32.exe
C:WINDOWSsttray.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32hkcmd.exe
C:WINDOWSsystem32igfxpers.exe
C:Program FilesJavajre1.6.0_05binjusched.exe
C:Program FilesAheadInCDInCD.exe
C:Program FilesFichiers communsRealUpdate_OBrealsched.exe
C:Program FilesPC Tools AntiVirusPCTAV.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE
C:Program FilesDNAbtdna.exe
C:Program FilesCursorXPCursorXP.exe
C:WINDOWSsystem32rundll32.exe
C:Program FilesWindows Media PlayerWMPNSCFG.exe
C:Program FilesSpybot - Search & DestroyTeaTimer.exe
C:Program FilesLClockLClock.exe
C:Program FilesStardockObjectDockObjectDock.exe
C:WINDOWSsystem32rundll32.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesFichiers communsMicrosoft SharedWindows LiveWLLoginProxy.exe
C:PROGRA~1DVDREG~1DVDRegionFree.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://neufportail.fr/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = https://home.sweetim.com/
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:Program FilesRealRealPlayerrpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:WINDOWSsystem32nnnLcCVl.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:WINDOWSsystem32wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_05binssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesFichiers communsMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesWindows Live Toolbarmsntb.dll
O2 - BHO: (no name) - {DD4A65C7-61D7-445F-BCF1-5065F765EAF9} - C:WINDOWSsystem32urqPgDtR.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:Program FilesEPSONEPSON Web-To-PageEPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:Program FilesEPSONEPSON Web-To-PageEPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:Program FilesWindows Live Toolbarmsntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar1.dll
O4 - HKLM..Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [Recguard] C:WINDOWSSMINSTRECGUARD.EXE
O4 - HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [Persistence] C:WINDOWSsystem32igfxpers.exe
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_05binjusched.exe"
O4 - HKLM..Run: [InCD] C:Program FilesAheadInCDInCD.exe
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [ISUSPM] "C:Program FileseMuleIncomingCommonInstallShieldUpdateServiceISUSPM.exe" -scheduler
O4 - HKLM..Run: [01234567890123456789012345678901234567890123456789012345678901234567890123456789012345678 901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678 9012345678901234567890123456789012345678901234567890123456789012345678912345678] C:Program Filesuser32.exe
O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [TkBellExe] "C:Program FilesFichiers communsRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [PCTAVApp] "C:Program FilesPC Tools AntiVirusPCTAV.exe" /MONITORSCAN
O4 - HKLM..Run: [BM438aa6a1] Rundll32.exe "C:WINDOWSsystem32qpchvjaa.dll",s
O4 - HKLM..Run: [40b9953d] rundll32.exe "C:WINDOWSsystem32pkccyrou.dll",b
O4 - HKLM..RunServices: [MSys32] "C:Program FilesTetris 3000datamorfitwebentrance.exe"
O4 - HKLM..RunOnce: [Spybot - Search & Destroy] "C:Program FilesSpybot - Search & DestroySpybotSD.exe" /autocheck
O4 - HKLM..RunOnce: [SpybotDeletingA6554] command /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKLM..RunOnce: [SpybotDeletingC8130] cmd /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKLM..RunOnce: [SpybotDeletingA8001] command /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKLM..RunOnce: [SpybotDeletingC7784] cmd /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [NBJ] "C:Program FilesAheadNero BackItUpnbj.exe"
O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - HKCU..Run: [AlertEmail] C:Program FilesAlertEmailalertemail.exe
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [Internet Download Accelerator] C:Program FilesIDAida.exe -autorun
O4 - HKCU..Run: [BitTorrent DNA] "C:Program FilesDNAbtdna.exe"
O4 - HKCU..Run: [CursorXP] C:Program FilesCursorXPCursorXP.exe
O4 - HKCU..Run: [Netlog 24] "C:Program FilesNetlog 24NotifierNetlog24Notifier.exe"
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKCU..RunOnce: [SpybotDeletingB5548] command /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKCU..RunOnce: [SpybotDeletingD1483] cmd /c del "C:WINDOWSsystem32nnnLcCVl.dll_old"
O4 - HKCU..RunOnce: [SpybotDeletingB9066] command /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKCU..RunOnce: [SpybotDeletingD838] cmd /c del "C:WINDOWSsystem32wvUKDTKc.dll_old"
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:Program FilesLClockLClock.exe
O4 - Startup: ObjectDock.lnk = C:Program FilesStardockObjectDockObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:Program FilesUBISOFTPrince of Persia l'Ame du GuerrierSupportRegisterRegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:Program FilesUberIconUberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:Program Files3Deep Space3D Solar System Screensaverunins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:Program FilesGoogleGoogle UpdaterGoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:Program FilesMicrosoft SQL Server80ToolsBinnsqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:Program FilesWindows Desktop SearchWindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:Program FilesWindows Live Toolbarmsntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_05binssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_05binssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncinetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncinetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncinetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - https://copainsdavant.linternaute.com/
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: urqPgDtR - C:WINDOWSSYSTEM32urqPgDtR.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:Program FilesLavasoftAd-Aware 2007aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:Program FilesFichiers communsMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesFichiers communsInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:Program FilesAheadInCDInCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:Program FilesiPodbiniPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:Program FilesCDBurnerXP Pro 3ToolsNMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:Program FilesCDBurnerXPNMSAccessU.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:Program FilesPC Tools AntiVirusPCTAVSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:WINDOWSsystem32PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:WINDOWSsystem32PnkBstrB.exe
O23 - Service: L Ile Noyee Drivers Auto Removal (pr2ajbeb) (pr2ajbeb) - Micro Application - C:WINDOWSsystem32pr2ajbeb.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared filesRichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:Program FilesSigmaTelC-Major AudioWDMSTacSV.exe
--
End of file - 15919 bytes
merci
A voir également:
- Erreur 1058 windows update windows 10
- Erreur 0x80070643 - Accueil - Windows
- Une erreur s'est produite instagram ✓ - Forum Instagram
- Erreur 0x80070643 Windows 10 : comment résoudre le problème de la mise à jour KB5001716 - Accueil - Windows
- Erreur 1001 outlook - Accueil - Bureautique
- Erreur 3000 france tv - Forum Lecteurs et supports vidéo
34 réponses
higelin22
Messages postés
263
Date d'inscription
mardi 27 mai 2008
Statut
Membre
Dernière intervention
17 juin 2008
15
29 mai 2008 à 01:34
29 mai 2008 à 01:34
HiJackThis est un logiciel destiné à tous les utilisateurs victimes d’attaques sur Internet. Généralement, ce type d'attaque est caractérisé par l'apparition soudaine de barres de recherche, du changement de la page d'accueil, ainsi que par une chute aggravée des performances de votre machine. HiJackThis vous aide à localiser ces programmes mal intentionnés, et ainsi vous permettre de les supprimer.
De plus, il va vous faciliter la résolution du problème en forçant la page d'accueil de votre navigateur Internet Explorer, souvent encombrée par les programmes espions, et permettre une sauvegarde des paramètres dans le but d'une restauration ultérieure.
De plus, il va vous faciliter la résolution du problème en forçant la page d'accueil de votre navigateur Internet Explorer, souvent encombrée par les programmes espions, et permettre une sauvegarde des paramètres dans le but d'une restauration ultérieure.
g!rly
Messages postés
18209
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
406
29 mai 2008 à 16:52
29 mai 2008 à 16:52
Salut lyykane,
desinstale spybot
puis
passe ceci stp
Télécharge combofix.exe (par sUBs) sur ton Bureau.
-> http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
-> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Post egalement un nouveu rapport hijack this stp
@+
desinstale spybot
puis
passe ceci stp
Télécharge combofix.exe (par sUBs) sur ton Bureau.
-> http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
-> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Post egalement un nouveu rapport hijack this stp
@+
Salut
J'ai exactement le même problème depuis hier soir...
Si quelqu'un a une solution cela serais gentil de nous aider...
Merci d'avance
Amicalement
J'ai exactement le même problème depuis hier soir...
Si quelqu'un a une solution cela serais gentil de nous aider...
Merci d'avance
Amicalement
Moi aussi j'ai le même problème, impossible d'activer les mises à jour automatiques et surtout Internet Explorer qui rame à fond et des fenêtres intempestives qui s'ouvraient. J'ai réussi à mettre un terme à ces fenêtres en désactivant les modules complémentaires, mais ça rame toujours.
Quand je suis dans service.msc, et que je mets automatique puis "démarrer" (quand ça s'affiche, c à d une fois sur dix), j'ai "erreur 1058".
Et Norton qui me dit que tout va bien y compris les mises à jour automatiques... Je vais essayer avec malwarebytes, comme vous.
Il doit y avoir un virus récent qu'on a chopé.
Jérémie.
Quand je suis dans service.msc, et que je mets automatique puis "démarrer" (quand ça s'affiche, c à d une fois sur dix), j'ai "erreur 1058".
Et Norton qui me dit que tout va bien y compris les mises à jour automatiques... Je vais essayer avec malwarebytes, comme vous.
Il doit y avoir un virus récent qu'on a chopé.
Jérémie.
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
22 mai 2008 à 20:46
22 mai 2008 à 20:46
Salut et bien ça y est comme une grande je n'ai plus de virus en fait j'ai fait un scan complet avec malwarebytes et il m'a débarrassé de tout les virus. Le petit prob c'est qu'il revient et j'aimerai m'en débarassé définitivement mais bon un scan intelligent de malwarebytes et c'est résolu. voilà c'est tou ce que je peux te conseiller. Attention le scan est très long surtout si tu as beaucoup de dossiers.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
higelin22
Messages postés
263
Date d'inscription
mardi 27 mai 2008
Statut
Membre
Dernière intervention
17 juin 2008
15
29 mai 2008 à 01:26
29 mai 2008 à 01:26
oui en effet c'est le bronx la dedans
g!rly
Messages postés
18209
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
406
29 mai 2008 à 16:57
29 mai 2008 à 16:57
De rien :)
Enfin faudrait il qu´il revienne ?!
@+
Enfin faudrait il qu´il revienne ?!
@+
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
29 mai 2008 à 18:17
29 mai 2008 à 18:17
ComboFix 08-05-28.8 - sabine 2008-05-29 17:52:29.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.570 [GMT 2:00]
Endroit: C:\Documents and Settings\sabine\Mes documents\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\BM438aa6a1.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aesrboam.ini
C:\WINDOWS\system32\asgmkobl.dll
C:\WINDOWS\system32\bidlowub.dll
C:\WINDOWS\system32\cbgkdrkv.ini
C:\WINDOWS\system32\cKTDKUvw.ini
C:\WINDOWS\system32\cKTDKUvw.ini2
C:\WINDOWS\system32\cnacrmim.ini
C:\WINDOWS\system32\cwvxnjcx.ini
C:\WINDOWS\system32\dchocaud.dll
C:\WINDOWS\system32\dgxerpgh.ini
C:\WINDOWS\system32\dpujivgk.ini
C:\WINDOWS\system32\dsnbfxcn.ini
C:\WINDOWS\system32\eNWwyGgh.ini
C:\WINDOWS\system32\eNWwyGgh.ini2
C:\WINDOWS\system32\fecnvgxq.exe
C:\WINDOWS\system32\fgvxxjyp.dll
C:\WINDOWS\system32\fxsqbebs.ini
C:\WINDOWS\system32\gqtyjdec.ini
C:\WINDOWS\system32\hsvtotgd.exe
C:\WINDOWS\system32\jfqjxfrv.ini
C:\WINDOWS\system32\jjnnbjmj.ini
C:\WINDOWS\system32\jmboohsa.ini
C:\WINDOWS\system32\jvsbnhsy.ini
C:\WINDOWS\system32\kpmkuxgs.ini
C:\WINDOWS\system32\kuxyeyox.ini
C:\WINDOWS\system32\lawhrpea.ini
C:\WINDOWS\system32\lbdyxvtv.dll
C:\WINDOWS\system32\lfmaywau.ini
C:\WINDOWS\system32\lfqfqtbb.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mprhhldh.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mxqfdchj.dll
C:\WINDOWS\system32\oorwflya.dll
C:\WINDOWS\system32\oxpfshxh.ini
C:\WINDOWS\system32\pnraslbb.ini
C:\WINDOWS\system32\pqluulut.ini
C:\WINDOWS\system32\qgxseftd.dll
C:\WINDOWS\system32\qpchvjaa.dll
C:\WINDOWS\system32\qxqsnjvr.ini
C:\WINDOWS\system32\rihifnsc.ini
C:\WINDOWS\system32\tbcvkmfi.exe
C:\WINDOWS\system32\tbeoykfm.ini
C:\WINDOWS\system32\tbshxfeo.ini
C:\WINDOWS\system32\tcmocyyh.ini
C:\WINDOWS\system32\toliepgm.dll
C:\WINDOWS\system32\ukqetrbh.ini
C:\WINDOWS\system32\uorycckp.ini
C:\WINDOWS\system32\wsehkamc.ini
C:\WINDOWS\system32\wslcrlfc.exe
C:\WINDOWS\system32\xamrscqm.ini
C:\WINDOWS\system32\yjjsetrf.ini
C:\WINDOWS\system32\yupbqtyh.exe
C:\WINDOWS\system32\ywsmsubd.ini
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-28 to 2008-05-29 ))))))))))))))))))))))))))))))))))))
.
2008-05-29 13:24 . 2004-07-29 02:23 172,032 --a------ C:\WINDOWS\system32\LameACM.acm
2008-05-29 13:24 . 2004-07-29 02:23 172,032 --a------ C:\lameACM.acm
2008-05-29 13:24 . 2004-08-22 06:48 1,720 --a------ C:\LameACM.inf
2008-05-29 13:24 . 2002-04-07 14:17 401 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-05-29 13:24 . 2002-04-07 14:17 401 --a------ C:\lame_acm.xml
2008-05-20 10:08 . 2008-05-20 10:08 <REP> d-------- C:\WINDOWS\McAfee.com
2008-05-20 09:46 . 2008-03-01 14:58 6,032,384 --a--c--- C:\WINDOWS\system32\dllcache\nsj8.tmp
2008-05-19 17:53 . 2008-05-19 17:53 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-19 14:31 . 2008-05-28 18:10 269 --a------ C:\WINDOWS\wininit.ini
2008-05-19 14:06 . 2008-05-19 14:06 <REP> d-------- C:\Program Files\Lavasoft
2008-05-19 14:06 . 2008-05-19 14:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-19 14:05 . 2008-05-19 14:05 <REP> d-------- C:\Program Files\Trend Micro
2008-05-19 14:05 . 2008-05-19 14:05 <REP> d-------- C:\Documents and Settings\laurent\Application Data\Malwarebytes
2008-05-19 14:02 . 2008-05-29 17:48 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-19 14:02 . 2008-05-19 14:02 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-19 14:02 . 2008-05-29 17:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-19 14:02 . 2008-05-19 14:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-19 14:02 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-19 14:02 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-19 12:01 . 2008-05-29 17:51 <REP> d-------- C:\Program Files\PC Tools AntiVirus
2008-05-19 12:01 . 2008-05-19 12:01 <REP> d-------- C:\Program Files\Fichiers communs\PC Tools
2008-05-19 12:01 . 2008-05-19 12:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-05-19 12:01 . 2007-12-06 15:51 28,568 --a------ C:\WINDOWS\system32\drivers\AVHook.sys
2008-05-19 12:01 . 2007-12-06 15:51 21,912 --a------ C:\WINDOWS\system32\drivers\AVRec.sys
2008-05-19 12:01 . 2008-02-12 10:44 21,904 --a------ C:\WINDOWS\system32\drivers\AVFilter.sys
2008-05-18 20:40 . 2008-05-18 20:40 125,952 --a------ C:\WINDOWS\system32\toliepgm.VIR000
2008-05-17 21:37 . 2008-05-17 21:37 371,712 --a------ C:\WINDOWS\system32\nnnLcCVl.VIR
2008-05-16 09:38 . 2008-05-16 09:46 <REP> d-------- C:\Program Files\AVPersonalPremium
2008-05-13 10:25 . 2008-05-13 16:41 <REP> d-------- C:\Program Files\Larousse
2008-05-09 15:03 . 2008-05-09 15:03 <REP> dr-h----- C:\MSOCache
2008-05-02 20:56 . 2008-05-20 21:16 <REP> d-------- C:\Program Files\Astro Avenger 2
2008-05-02 20:56 . 2008-05-02 20:56 <REP> d-------- C:\Documents and Settings\laurent\Application Data\Sahmon Games
2008-05-01 21:49 . 2008-05-01 21:49 <REP> d-------- C:\WINDOWS\msdownld.tmp
2008-05-01 21:42 . 2008-05-01 21:42 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-01 21:42 . 2008-05-01 21:42 22,328 --a------ C:\Documents and Settings\laurent\Application Data\PnkBstrK.sys
2008-05-01 21:41 . 2008-05-01 21:41 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-01 21:41 . 2008-05-01 21:41 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-01 21:41 . 2008-05-01 21:41 319 --a------ C:\WINDOWS\game.ini
2008-05-01 21:21 . 2008-05-01 21:21 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-05-01 18:40 . 2008-05-01 18:40 <REP> d-------- C:\Program Files\Traction Software
2008-04-29 14:27 . 2008-05-19 22:23 38 --a------ C:\Documents and Settings\laurent\launcher.dat
2008-04-29 14:11 . 2008-04-29 14:11 <REP> d-------- C:\Team17
2008-04-29 14:08 . 1997-08-26 12:06 315,904 --a------ C:\WINDOWS\IsUninst.exe
2008-04-29 14:07 . 2008-04-29 14:09 47,104 --a------ C:\WINDOWS\system32\KMVIDC32.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 16:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-29 15:59 --------- d-----w C:\Documents and Settings\laurent\Application Data\DNA
2008-05-29 13:31 --------- d-----w C:\Program Files\eMule
2008-05-29 11:22 --------- d-----w C:\Program Files\Video Convert Master
2008-05-29 09:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-29 08:47 --------- d-----w C:\Documents and Settings\laurent\Application Data\BitTorrent
2008-05-28 12:33 --------- d-----w C:\Program Files\Jewel Quest Solitaire
2008-05-20 19:18 --------- d-----w C:\Program Files\Kyodai Mahjongg
2008-05-20 14:50 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-19 14:41 --------- d-----w C:\Program Files\Elf Bowling The Last Insult
2008-05-19 14:40 --------- d-----w C:\Program Files\Jewel Quest Solitaire II
2008-05-19 14:39 --------- d-----w C:\Program Files\Micro Application
2008-05-19 14:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-19 13:28 8,192 --sha-w C:\Program Files\Thumbs.db
2008-05-19 10:04 --------- d-----w C:\Documents and Settings\laurent\Application Data\PC Tools
2008-05-18 18:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-05-15 20:51 92,232 ----a-w C:\Documents and Settings\laurent\Application Data\GDIPFONTCACHEV1.DAT
2008-05-13 01:47 --------- d-----w C:\Program Files\BitTorrent
2008-05-02 16:26 3,532 ----a-w C:\drmHeader.bin
2008-04-30 09:05 --------- d-----w C:\Program Files\Mah Jong Quest II
2008-04-30 09:05 --------- d-----w C:\Program Files\Brickshooter Egypt
2008-04-30 09:04 --------- d-----w C:\Program Files\Race Cars The Extreme Rally
2008-04-29 12:16 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-28 16:22 --------- d-----w C:\Program Files\Mad Cars
2008-04-25 08:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-04-25 08:29 --------- d-----w C:\Program Files\Bonjour
2008-04-23 14:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-23 14:22 --------- d-----w C:\Program Files\Fichiers communs\Macrovision Shared
2008-04-22 18:22 --------- d-----w C:\Documents and Settings\laurent\Application Data\gtk-2.0
2008-04-22 16:07 --------- d-----w C:\Program Files\ACD Systems
2008-04-20 18:56 --------- d-----w C:\Program Files\Totem Quest
2008-04-20 16:39 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-04-11 19:14 --------- d-----w C:\Program Files\Big Kahuna Reef
2008-04-10 06:19 --------- d-----w C:\Program Files\DivX
2008-04-09 09:56 --------- d-----w C:\Program Files\Alcohol Soft
2008-04-09 08:42 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-04-06 09:37 3,699,424 ----atw C:\WINDOWS\DXM1F1.tmp
2008-04-06 07:58 --------- d-----w C:\Program Files\D-Tools
2008-04-05 19:34 --------- d-----w C:\Program Files\Netlog 24
2008-04-05 14:54 --------- d-----w C:\Documents and Settings\laurent\Application Data\Windows Live Writer
2008-04-05 14:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-02 10:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2008-03-29 20:58 --------- d-----w C:\Program Files\LClock
2008-03-29 20:58 --------- d-----w C:\Program Files\iColorFolder
2008-03-29 20:56 --------- d-----w C:\Program Files\CursorXP
2008-03-29 20:49 --------- d-----w C:\Program Files\Act 3d
2008-03-29 20:47 79,435 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-03-29 20:47 2,355 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-03-29 20:47 --------- d-----w C:\Program Files\UberIcon
2008-03-29 20:47 --------- d-----w C:\Program Files\Stardock
2008-03-28 14:55 --------- d-----w C:\Documents and Settings\laurent\Application Data\iWin
2008-03-16 15:20 98,304 ----a-w C:\WINDOWS\DUMP3345.tmp
2008-03-02 14:47 0 ----a-w C:\Program Files\temp01
2007-11-03 21:49 47,360 ----a-w C:\Documents and Settings\laurent\Application Data\pcouffin.sys
2007-05-08 19:51 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-02-13 17:56 10,240 --sha-w C:\WINDOWS\rnapxs\rnapxs.dat
2007-11-02 16:04 56 --sh--r C:\WINDOWS\system32\5C84FAE664.sys
2007-11-02 16:04 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2005-03-03 03:20 578048 c34920eb988ce98910bd6b0417f334eb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 17:50 579072 4d88aaf39adabfe45958ea1384e2c4ff C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-05 21:00 578048 e46fb493e3b33704f0715020cf52106b C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-03 03:10 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2007-03-08 17:37 572928 aecdb362e13a761bb7494dcdffdda575 C:\WINDOWS\system32\user32.dll
2007-03-08 17:37 572928 aecdb362e13a761bb7494dcdffdda575 C:\WINDOWS\system32\dllcache\user32.dll
2007-06-13 15:22 4457984 35478020b7c8b03a95a6e896e4857cf5 C:\WINDOWS\explorer.exe
2007-06-13 15:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-05 21:00 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 15:22 4457984 35478020b7c8b03a95a6e896e4857cf5 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-03-19_11.49.33.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-20 07:56:50 1,846,016 ----a-w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll
+ 2008-02-20 05:20:23 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:50:24 45,568 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\updspapi.dll
+ 2008-03-01 12:34:26 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\advpack.dll
+ 2008-03-01 12:34:26 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtmsft.dll
+ 2008-03-01 12:34:26 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtrans.dll
+ 2008-03-01 12:34:27 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\extmgr.dll
+ 2008-03-01 12:34:27 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\icardie.dll
+ 2008-02-22 09:39:56 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ie4uinit.exe
+ 2008-03-01 12:34:27 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakeng.dll
+ 2008-03-01 12:34:27 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieaksie.dll
+ 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dat
+ 2008-03-01 12:34:27 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dll
+ 2008-03-01 12:34:27 388,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iedkcs32.dll
+ 2008-03-01 12:34:29 6,067,712 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieframe.dll
+ 2008-03-01 12:34:29 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iernonce.dll
+ 2008-03-01 12:34:29 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iertutil.dll
+ 2008-02-22 09:39:56 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieudinit.exe
+ 2008-02-22 09:40:22 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
+ 2008-03-01 12:34:30 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\jsproxy.dll
+ 2008-03-01 12:34:30 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeeds.dll
+ 2008-03-01 12:34:30 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeedsbs.dll
+ 2008-03-01 12:34:32 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
+ 2008-03-01 12:34:32 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtmled.dll
+ 2008-03-01 12:34:32 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msrating.dll
+ 2008-03-01 12:34:32 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mstime.dll
+ 2008-03-01 12:34:32 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\occache.dll
+ 2008-03-01 12:34:32 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\pngfilt.dll
+ 2008-03-01 12:34:32 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\url.dll
+ 2008-03-01 12:34:33 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\urlmon.dll
+ 2008-03-01 12:34:33 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\webcheck.dll
+ 2008-03-01 12:34:33 827,392 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\updspapi.dll
+ 2008-02-20 06:52:42 282,624 ----a-w C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\updspapi.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\update.exe
+ 2007-03-06 01:35:47 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\updspapi.dll
+ 2008-01-23 04:56:21 554,008 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\dao360.dll
+ 2007-12-10 12:41:11 518,944 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexch40.dll
+ 2007-12-10 12:41:11 326,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
+ 2007-12-10 12:41:11 1,516,568 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjet40.dll
+ 2007-12-10 12:41:11 355,112 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
+ 2008-03-25 06:56:31 194,144 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjint40.dll
+ 2007-12-10 12:41:12 60,192 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjter40.dll
+ 2007-12-10 12:41:12 248,608 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
+ 2007-12-10 12:41:12 219,936 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msltus40.dll
+ 2007-12-10 12:41:12 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
+ 2007-12-10 12:41:13 432,928 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
+ 2007-12-10 12:41:13 322,336 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
+ 2007-12-10 12:41:13 559,904 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
+ 2007-12-10 12:41:13 264,992 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mstext40.dll
+ 2007-12-10 12:41:13 838,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
+ 2007-11-01 05:15:27 621,344 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
+ 2007-12-10 12:41:14 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\updspapi.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\updspapi.dll
+ 2007-03-08 15:33:58 1,843,712 -c----w C:\WINDOWS\$NtUninstallKB941693$\win32k.sys
+ 2006-06-26 17:41:32 148,480 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsapi.dll
+ 2004-08-05 19:00:00 45,568 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsrslvr.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\updspapi.dll
+ 2007-06-19 13:32:25 282,112 -c----w C:\WINDOWS\$NtUninstallKB948590$\gdi32.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\updspapi.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe
+ 2007-03-06 01:35:47 394,976 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\updspapi.dll
- 2008-02-23 13:46:41 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-05-01 19:43:41 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-02-23 13:46:41 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-05-01 19:43:41 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-02-23 13:46:42 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-05-01 19:43:42 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-02-23 13:46:36 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:34 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:36 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:35 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:37 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:35 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:38 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:36 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:38 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:37 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:39 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:37 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:39 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:38 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:39 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:39 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:40 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:39 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:42 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:42 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:42 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-05-01 19:43:43 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-02-23 13:46:43 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-05-01 19:43:43 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-02-23 13:46:43 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-05-01 19:43:44 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-02-23 13:46:43 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-05-01 19:43:44 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-02-23 13:46:40 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-05-01 19:43:40 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-05-29 16:00:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-09-29 20:16:02 789,576 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\cursorxp_free_G3o.exe
+ 2005-08-22 17:19:54 94,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Pack It!.exe
+ 2004-08-05 19:00:00 542,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\100_themeui.dll
+ 2004-08-05 19:00:00 1,273,344 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\101_upnpui.dll
+ 2007-12-07 02:08:34 489,472 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\102_url.dll
+ 2007-12-07 02:08:34 1,643,520 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\103_Urlmon.dll
+ 2007-03-08 15:37:50 572,928 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\104_user32.dll
+ 2004-08-05 19:00:00 2,722,304 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\105_wab32res.dll
+ 2004-08-05 19:00:00 172,032 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\106_Wabfind.dll
+ 2007-12-07 02:08:34 1,451,008 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\107_webcheck.dll
+ 2004-08-05 19:00:00 571,392 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\108_wiadefui.dll
+ 2004-08-05 19:00:00 2,117,120 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\109_wiashext.dll
+ 2007-12-07 02:08:34 2,050,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\110_Wininet.dll
+ 2004-08-05 19:00:00 910,336 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\111_Winntbbu.dll
+ 2007-03-17 13:44:47 431,616 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\112_winsrv.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\114_wuaueng.dll
+ 2004-08-05 19:00:00 11,538,432 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\115_xpsp2res.dll
+ 2004-08-05 19:00:00 1,474,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\116_zipfldr.dll
+ 2004-08-05 19:00:00 650,240 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\117_accwiz.exe
+ 2004-08-05 19:00:00 198,144 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\118_ahui.exe
+ 2004-08-05 19:00:00 215,040 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\119_calc.exe
+ 2004-08-05 19:00:00 164,352 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\120_charmap.exe
+ 2004-08-05 19:00:00 467,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\121_cleanmgr.exe
+ 2004-08-05 19:00:00 501,248 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\122_cmd.exe
+ 2004-08-05 19:00:00 314,368 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\123_Drwtsn32.exe
+ 2007-06-13 13:22:28 4,457,984 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\124_explorer.exe
+ 2004-08-05 19:00:00 220,672 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\125_Grpconv.exe
+ 2004-08-05 19:00:00 862,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\126_helpctr.exe
+ 2005-05-27 06:22:01 167,936 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\127_Hh.exe
+ 2004-08-05 19:00:00 111,616 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\128_hypertrm.exe
+ 2004-08-05 19:00:00 452,096 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\129_icwconn1.exe
+ 2004-08-05 19:00:00 249,856 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\130_icwconn2.exe
+ 2007-12-06 11:03:16 3,110,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\131_iexplore.exe
+ 2004-08-05 19:00:00 506,368 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\132_logon.scr
+ 2006-10-04 13:32:58 173,568 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\133_magnify.exe
+ 2004-08-05 19:00:00 386,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\134_migload.exe
+ 2004-08-05 19:00:00 153,600 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\135_migpwd.exe
+ 2004-08-05 19:00:00 1,328,128 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\136_migwiz.exe
+ 2004-08-05 19:00:00 583,168 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\137_mobsync.exe
+ 2004-08-05 19:00:00 3,691,520 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\138_moviemk.exe
+ 2004-08-05 19:00:00 321,536 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\139_msconfig.exe
+ 2004-08-05 19:00:00 481,280 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\140_msimn.exe
+ 2004-08-05 19:00:00 179,200 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\141_msinfo32.exe
+ 2004-08-05 19:00:00 166,912 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\142_msoobe.exe
+ 2004-08-05 19:00:00 543,232 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\143_mspaint.exe
+ 2006-11-07 08:06:47 2,462,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\144_mstsc.exe
+ 2006-10-04 13:32:55 194,048 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\145_narrator.exe
+ 2004-08-05 19:00:00 152,064 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\146_notepad.exe
+ 2004-08-05 19:00:00 140,288 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\147_notiflag.exe
+ 2004-08-05 19:00:00 180,224 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\149_odbcad32.exe
+ 2004-08-05 19:00:00 490,496 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\150_Oemig50.exe
+ 2004-08-05 19:00:00 151,552 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\151_oobebaln.exe
+ 2006-10-04 13:32:58 275,456 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\152_osk.exe
+ 2004-08-05 19:00:00 197,120 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\153_rasphone.exe
+ 2004-08-05 19:00:00 180,224 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\154_rcimlby.exe
+ 2004-08-05 19:00:00 1,063,936 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\155_regedit.exe
+ 2004-08-05 19:00:00 531,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\156_rstrui.exe
+ 2004-08-05 19:00:00 220,160 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\157_rtcshare.exe
+ 2004-08-05 19:00:00 426,496 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\158_sndrec32.exe
+ 2004-08-05 19:00:00 785,408 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\159_sndvol32.exe
+ 2004-08-05 19:00:00 149,504 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\160_syncapp.exe
+ 2004-08-05 19:00:00 531,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\161_sysocmgr.exe
+ 2004-08-05 19:00:00 633,344 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\162_taskmgr.exe
+ 2004-08-05 19:00:00 484,352 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\163_tourstart.exe
+ 2006-10-04 13:32:57 188,416 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\164_utilman.exe
+ 2004-08-05 19:00:00 184,832 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\165_wab.exe
+ 2004-08-05 19:00:00 1,975,808 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\166_wiaacmgr.exe
+ 2004-08-05 19:00:00 771,584 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\167_Winhlp32.exe
+ 2004-08-05 19:00:00 670,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\168_wordpad.exe
+ 2004-08-05 19:00:00 171,008 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\169_wpabaln.exe
+ 2007-07-30 17:19:16 215,384 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\170_wuauclt.exe
+ 2004-08-05 19:00:00 111,616 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\171_Write.exe
+ 2004-08-05 19:00:00 168,960 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\172_wupdmgr.exe
+ 2007-10-25 16:43:25 9,677,824 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\185_shell32.dll
+ 2004-08-05 19:00:00 1,503,744 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\186_msgina.dll
+ 2006-10-18 20:47:08 1,254,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\187_Audiodev.dll
+ 2006-11-03 09:03:34 9,638,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\188_wmploc.dll
+ 2006-11-03 08:59:00 178,688 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\189_wmplayer.exe
+ 2004-08-05 19:00:00 3,926,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\198_logonui.exe
+ 2004-08-05 19:00:00 641,024 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\28_Acctres.dll
+ 2007-01-04 14:01:53 1,345,536 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\30_Browseui.dll
+ 2004-08-05 19:00:00 325,120 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\31_cabview.dll
+ 2007-01-04 14:01:54 1,163,776 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\32_cdfview.dll
+ 2004-08-05 19:00:00 614,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\33_cmdial32.dll
+ 2004-08-05 19:00:00 867,328 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\34_cmprops.dll
+ 2004-08-05 19:00:00 342,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\35_Comdlg32.dll
+ 2004-08-05 19:00:00 404,992 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\36_compatui.dll
+ 2004-08-05 19:00:00 851,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\37_comres.dll
+ 2004-08-05 19:00:00 205,312 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\38_console.dll
+ 2004-08-05 19:00:00 326,656 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\39_credui.dll
+ 2004-08-05 19:00:00 1,597,440 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\40_cscui.dll
+ 2004-08-05 19:00:00 99,328 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\41_Deskadp.dll
+ 2004-08-05 19:00:00 178,176 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\42_Deskmon.dll
+ 2004-08-05 19:00:00 180,224 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\43_Deskperf.dll
+ 2004-08-05 19:00:00 724,480 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\44_devmgr.dll
+ 2004-08-05 19:00:00 348,672 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\45_els.dll
+ 2004-08-05 19:00:00 704,512 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\46_filemgmt.dll
+ 2004-08-05 19:00:00 226,304 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\47_Fldrclnr.dll
+ 2004-08-05 19:00:00 1,352,704 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\48_fontext.dll
+ 2004-08-05 19:00:00 1,334,272 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\50_hnetwiz.dll
+ 2004-08-05 19:00:00 507,904 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\51_hotplug.dll
+ 2004-08-05 19:00:00 268,288 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\52_Icmui.dll
+ 2004-08-05 19:00:00 397,312 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\53_Icwdial.dll
+ 2004-08-05 19:00:00 229,376 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\54_Icwres.dll
+ 2007-12-07 02:08:32 1,470,464 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\55_ieaksie.dll
+ 2006-11-07 20:03:36 340,480 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\56_Iepeers.dll
+ 2007-12-07 02:08:33 150,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\57_Iernonce.dll
+ 2006-11-07 02:26:42 206,848 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\58_Iesetup.dll
+ 2004-08-05 19:00:00 471,040 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\59_Inetcfg.dll
+ 2004-08-05 19:00:00 1,320,960 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\6_comctl32.dll
+ 2004-08-05 19:00:00 2,209,280 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\60_inetcplc.dll
+ 2004-08-05 19:00:00 717,312 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\61_keymgr.dll
+ 2004-08-05 19:00:00 463,872 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\62_mdminst.dll
+ 2004-08-05 19:00:00 1,100,288 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\63_mobsync.dll
+ 2004-08-05 19:00:00 481,792 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\64_Modemui.dll
+ 2004-08-05 19:00:00 345,088 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\65_moricons.dll
+ 2007-12-08 05:08:36 5,864,960 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\67_mshtml.dll
+ 2007-04-18 16:14:18 3,180,544 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\68_msi.dll
+ 2004-08-05 19:00:00 212,992 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\69_msident.dll
+ 2004-08-05 19:00:00 1,382,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\70_msieftp.dll
+ 2004-08-05 19:00:00 4,833,792 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\71_MSOERES.DLL
+ 2004-08-05 19:00:00 838,144 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\72_mstask.dll
+ 2006-12-11 13:44:01 1,973,248 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\73_Mstscax.dll
+ 2004-08-05 19:00:00 785,920 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\74_mycomput.dll
+ 2004-08-05 19:00:00 354,816 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\75_mydocs.dll
+ 2004-08-05 19:00:00 383,488 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\76_netid.dll
+ 2004-08-05 19:00:00 3,534,848 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\77_netplwiz.dll
+ 2004-08-05 19:00:00 7,938,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\78_netshell.dll
+ 2004-08-05 19:00:00 1,475,072 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\79_newdev.dll
+ 2004-08-05 19:00:00 1,450,496 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\8_comctl32.dll
+ 2004-08-05 19:00:00 661,504 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\80_ntshrui.dll
+ 2007-12-07 02:08:34 905,728 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\81_occache.dll
+ 2004-08-05 19:00:00 390,656 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\82_photowiz.dll
+ 2004-08-05 19:00:00 1,474,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\83_printui.dll
+ 2004-08-05 19:00:00 2,534,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\84_rasdlg.dll
+ 2004-08-05 19:00:00 200,704 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\85_remotepg.dll
+ 2004-08-05 19:00:00 115,712 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\86_sendmail.dll
+ 2004-08-05 19:00:00 1,281,024 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\87_setupapi.dll
+ 2004-08-05 19:00:00 293,888 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\88_sfc_os.dll
+ 2004-08-05 19:00:00 1,946,624 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\89_shdoclc.dll
+ 2007-01-04 14:02:16 4,751,360 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\90_shdocvw.dll
+ 2004-08-05 19:00:00 1,137,664 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\91_shimgvw.dll
+ 2007-01-04 14:02:17 633,344 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\92_SHLWAPI.DLL
+ 2004-08-05 19:00:00 3,271,230 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\93_srchui.dll
+ 2004-08-05 19:00:00 406,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\94_srrstr.dll
+ 2004-08-05 19:00:00 678,912 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\95_sti_ci.dll
+ 2004-08-05 19:00:00 607,232 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\96_stobject.dll
+ 2004-08-05 19:00:00 333,824 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\97_syncui.dll
+ 2004-08-05 19:00:00 3,299,328 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\98_syssetup.dll
+ 2004-08-05 19:00:00 481,792 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\99_tapiui.dll
+ 2008-03-29 13:57:34 219,648 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\Ux_uxtheme.dll
+ 2008-03-29 20:47:39 244,459 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Remove.exe
+ 2007-12-07 10:40:08 15,310 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\173_logonui.exe\27.bin
+ 2007-12-07 10:37:22 2,228 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\1.bin
+ 2007-12-07 10:37:22 2,511 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\10.bin
+ 2007-12-07 10:37:22 2,511 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\11.bin
+ 2007-12-07 10:37:22 3,637 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\2.bin
+ 2007-12-07 10:37:22 3,643 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\3.bin
+ 2007-12-07 10:37:22 4,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\4.bin
+ 2007-12-07 10:37:22 4,901 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\5.bin
+ 2007-12-07 10:37:22 4,674 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\6.bin
+ 2007-12-07 10:37:22 3,570 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\7.bin
+ 2007-12-07 10:37:22 3,567 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\8.bin
+ 2007-12-07 10:37:22 3,562 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\9.bin
+ 2002-03-24 19:23:38 881,664 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResHacker\ResHacker.exe
+ 2007-12-07 10:40:10 246,594 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Update.exe
+ 2004-08-05 19:00:00 391,168 ----a-w C:\WINDOWS\BricoPacks\SysFiles\100_themeui.dll
+ 2004-08-05 19:00:00 240,128 ----a-w C:\WINDOWS\BricoPacks\SysFiles\101_upnpui.dll
+ 2007-12-07 02:08:34 105,984 ----a-w C:\WINDOWS\BricoPacks\SysFiles\102_url.dll
+ 2007-12-07 02:08:34 1,159,680 ----a-w C:\WINDOWS\BricoPacks\SysFiles\103_Urlmon.dll
+ 2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\BricoPacks\SysFiles\104_user32.dll
+ 2004-08-05 19:00:00 263,168 ----a-w C:\WINDOWS\BricoPacks\SysFiles\105_wab32res.dll
+ 2004-08-05 19:00:00 32,768 ----a-w C:\WINDOWS\BricoPacks\SysFiles\106_Wabfind.dll
+ 2007-12-07 02:08:34 233,472 ----a-w C:\WINDOWS\BricoPacks\SysFiles\107_webcheck.dll
+ 2004-08-05 19:00:00 465,920 ----a-w C:\WINDOWS\BricoPacks\SysFiles\108_wiadefui.dll
+ 2004-08-05 19:00:00 594,432 ----a-w C:\WINDOWS\BricoPacks\SysFiles\109_wiashext.dll
+ 2007-12-07 02:08:34 824,832 ----a-w C:\WINDOWS\BricoPacks\SysFiles\110_Wininet.dll
+ 2004-08-05 19:00:00 773,632 ----a-w C:\WINDOWS\BricoPacks\SysFiles\111_Winntbbu.dll
+ 2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\BricoPacks\SysFiles\112_winsrv.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\BricoPacks\SysFiles\114_wuaueng.dll
+ 2004-08-05 19:00:00 2,986,496 ----a-w C:\WINDOWS\BricoPacks\SysFiles\115_xpsp2res.dll
+ 2004-08-05 19:00:00 340,480 ----a-w C:\WINDOWS\BricoPacks\SysFiles\116_zipfldr.dll
+ 2004-08-05 19:00:00 189,952 ----a-w C:\WINDOWS\BricoPacks\SysFiles\117_accwiz.exe
+ 2004-08-05 19:00:00 98,304 ----a-w C:\WINDOWS\BricoPacks\SysFiles\118_ahui.exe
+ 2004-08-05 19:00:00 115,200 ----a-w C:\WINDOWS\BricoPacks\SysFiles\119_calc.exe
+ 2004-08-05 19:00:00 80,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\120_charmap.exe
+ 2004-08-05 19:00:00 65,536 ----a-w C:\WINDOWS\BricoPacks\SysFiles\121_cleanmgr.exe
+ 2004-08-05 19:00:00 400,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\122_cmd.exe
+ 2004-08-05 19:00:00 47,104 ----a-w C:\WINDOWS\BricoPacks\SysFiles\123_Drwtsn32.exe
+ 2007-06-13 13:22:28 1,037,312 ----a-w C:\WINDOWS\BricoPacks\SysFiles\124_explorer.exe
+ 2004-08-05 19:00:00 39,424 ----a-w C:\WINDOWS\BricoPacks\SysFiles\125_Grpconv.exe
+ 2004-08-05 19:00:00 768,512 ----a-w C:\WINDOWS\BricoPacks\SysFiles\126_helpctr.exe
+ 2005-05-27 06:22:01 10,752 ----a-w C:\WINDOWS\BricoPacks\SysFiles\127_Hh.exe
+ 2004-08-05 19:00:00 28,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\128_hypertrm.exe
+ 2004-08-05 19:00:00 218,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\129_icwconn1.exe
+ 2004-08-05 19:00:00 86,016 ----a-w C:\WINDOWS\BricoPacks\SysFiles\130_icwconn2.exe
+ 2007-12-06 11:03:16 625,664 ----a-w C:\WINDOWS\BricoPacks\SysFiles\131_iexplore.exe
+ 2004-08-05 19:00:00 221,696 ----a-w C:\WINDOWS\BricoPacks\SysFiles\132_logon.scr
+ 2006-10-04 13:32:58 73,216 ----a-w C:\WINDOWS\BricoPacks\SysFiles\133_magnify.exe
+ 2004-08-05 19:00:00 103,936 ----a-w C:\WINDOWS\BricoPacks\SysFiles\134_migload.exe
+ 2004-08-05 19:00:00 52,736 ----a-w C:\WINDOWS\BricoPacks\SysFiles\135_migpwd.exe
+ 2004-08-05 19:00:00 246,784 ----a-w C:\WINDOWS\BricoPacks\SysFiles\136_migwiz.exe
+ 2004-08-05 19:00:00 144,384 ----a-w C:\WINDOWS\BricoPacks\SysFiles\137_mobsync.exe
+ 2004-08-05 19:00:00 3,555,328 ----a-w C:\WINDOWS\BricoPacks\SysFiles\138_moviemk.exe
+ 2004-08-05 19:00:00 160,768 ----a-w C:\WINDOWS\BricoPacks\SysFiles\139_msconfig.exe
+ 2004-08-05 19:00:00 60,416 ----a-w C:\WINDOWS\BricoPacks\SysFiles\140_msimn.exe
+ 2004-08-05 19:00:00 40,448 ----a-w C:\WINDOWS\BricoPacks\SysFiles\141_msinfo32.exe
+ 2004-08-05 19:00:00 28,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\142_msoobe.exe
+ 2004-08-05 19:00:00 347,648 ----a-w C:\WINDOWS\BricoPacks\SysFiles\143_mspaint.exe
+ 2006-11-07 08:06:47 600,576 ----a-w C:\WINDOWS\BricoPacks\SysFiles\144_mstsc.exe
+ 2006-10-04 13:32:55 55,296 ----a-w C:\WINDOWS\BricoPacks\SysFiles\145_narrator.exe
+ 2004-08-05 19:00:00 70,656 ----a-w C:\WINDOWS\BricoPacks\SysFiles\146_notepad.exe
+ 2004-08-05 19:00:00 35,328 ----a-w C:\WINDOWS\BricoPacks\SysFiles\147_notiflag.exe
+ 2004-08-05 19:00:00 32,768 ----a-w C:\WINDOWS\BricoPacks\SysFiles\149_odbcad32.exe
+ 2004-08-05 19:00:00 60,928 ----a-w C:\WINDOWS\BricoPacks\SysFiles\150_Oemig50.exe
+ 2004-08-05 19:00:00 51,712 ----a-w C:\WINDOWS\BricoPacks\SysFiles\151_oobebaln.exe
+ 2006-10-04 13:32:58 216,576 ----a-w C:\WINDOWS\BricoPacks\SysFiles\152_osk.exe
+ 2004-08-05 19:00:00 57,344 ----a-w C:\WINDOWS\BricoPacks\SysFiles\153_rasphone.exe
+ 2004-08-05 19:00:00 35,840 ----a-w C:\WINDOWS\BricoPacks\SysFiles\154_rcimlby.exe
+ 2004-08-05 19:00:00 153,088 ----a-w C:\WINDOWS\BricoPacks\SysFiles\155_regedit.exe
+ 2004-08-05 19:00:00 384,512 ----a-w C:\WINDOWS\BricoPacks\SysFiles\156_rstrui.exe
+ 2004-08-05 19:00:00 78,336 ----a-w C:\WINDOWS\BricoPacks\SysFiles\157_rtcshare.exe
+ 2004-08-05 19:00:00 133,120 ----a-w C:\WINDOWS\BricoPacks\SysFiles\158_sndrec32.exe
+ 2004-08-05 19:00:00 139,264 ----a-w C:\WINDOWS\BricoPacks\SysFiles\159_sndvol32.exe
+ 2004-08-05 19:00:00 51,200 ----a-w C:\WINDOWS\BricoPacks\SysFiles\160_syncapp.exe
+ 2004-08-05 19:00:00 107,520 ----a-w C:\WINDOWS\BricoPacks\SysFiles\161_sysocmgr.exe
+ 2004-08-05 19:00:00 143,360 ----a-w C:\WINDOWS\BricoPacks\SysFiles\162_taskmgr.exe
+ 2004-08-05 19:00:00 347,136 ----a-w C:\WINDOWS\BricoPacks\SysFiles\163_tourstart.exe
+ 2006-10-04 13:32:57 50,176 ----a-w C:\WINDOWS\BricoPacks\SysFiles\164_utilman.exe
+ 2004-08-05 19:00:00 46,080 ----a-w C:\WINDOWS\BricoPacks\SysFiles\165_wab.exe
+ 2004-08-05 19:00:00 438,784 ----a-w C:\WINDOWS\BricoPacks\SysFiles\166_wiaacmgr.exe
+ 2004-08-05 19:00:00 288,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\167_Winhlp32.exe
+ 2004-08-05 19:00:00 218,112 ----a-w C:\WINDOWS\BricoPacks\SysFiles\168_wordpad.exe
+ 2004-08-05 19:00:00 32,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\169_wpabaln.exe
+ 2007-07-30 17:19:16 53,080 ----a-w C:\WINDOWS\BricoPacks\SysFiles\170_wuauclt.exe
+ 2004-08-05 19:00:00 5,632 ----a-w C:\WINDOWS\BricoPacks\SysFiles\171_Write.exe
+ 2004-08-05 19:00:00 32,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\172_wupdmgr.exe
+ 2007-10-25 16:43:25 8,516,608 ----a-w C:\WINDOWS\BricoPacks\SysFiles\185_shell32.dll
+ 2004-08-05 19:00:00 1,004,032 ----a-w C:\WINDOWS\BricoPacks\SysFiles\186_msgina.dll
+ 2006-10-18 20:47:08 276,992 ----a-w C:\WINDOWS\BricoPacks\SysFiles\187_Audiodev.dll
+ 2006-11-03 09:03:34 8,292,352 ----a-w C:\WINDOWS\BricoPacks\SysFiles\188_wmploc.dll
+ 2006-11-03 08:59:00 64,000 ----a-w C:\WINDOWS\BricoPacks\SysFiles\189_wmplayer.exe
+ 2004-08-05 19:00:00 515,584 ----a-w C:\WINDOWS\BricoPacks\SysFiles\198_logonui.exe
+ 2004-06-18 12:07:33 656,542 ----a-w C:\WINDOWS\BricoPacks\SysFiles\218_icolorfolder.dll
+ 2004-08-05 19:00:00 72,192 ----a-w C:\WINDOWS\BricoPacks\SysFiles\28_Acctres.dll
+ 2007-01-04 14:01:53 1,023,488 ----a-w C:\WINDOWS\BricoPacks\SysFiles\30_Browseui.dll
+ 2004-08-05 19:00:00 85,504 ----a-w C:\WINDOWS\BricoPacks\SysFiles\31_cabview.dll
+ 2007-01-04 14:01:54 152,064 ----a-w C:\WINDOWS\BricoPacks\SysFiles\32_cdfview.dll
+ 2004-08-05 19:00:00 352,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\33_cmdial32.dll
+ 2004-08-05 19:00:00 191,488 ----a-w C:\WINDOWS\BricoPacks\SysFiles\34_cmprops.dll
+ 2004-08-05 19:00:00 281,088 ----a-w C:\WINDOWS\BricoPacks\SysFiles\35_Comdlg32.dll
+ 2004-08-05 19:00:00 253,440 ----a-w C:\WINDOWS\BricoPacks\SysFiles\36_compatui.dll
+ 2004-08-05 19:00:00 851,968 ----a-w C:\WINDOWS\BricoPacks\SysFiles\37_comres.dll
+ 2004-08-05 19:00:00 67,072 ----a-w C:\WINDOWS\BricoPacks\SysFiles\38_console.dll
+ 2004-08-05 19:00:00 165,888 ----a-w C:\WINDOWS\BricoPacks\SysFiles\39_credui.dll
+ 2004-08-05 19:00:00 337,920 ----a-w C:\WINDOWS\BricoPacks\SysFiles\40_cscui.dll
+ 2004-08-05 19:00:00 16,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\41_Deskadp.dll
+ 2004-08-05 19:00:00 16,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\42_Deskmon.dll
+ 2004-08-05 19:00:00 18,944 ----a-w C:\WINDOWS\BricoPacks\SysFiles\43_Deskperf.dll
+ 2004-08-05 19:00:00 290,816 ----a-w C:\WINDOWS\BricoPacks\SysFiles\44_devmgr.dll
+ 2004-08-05 19:00:00 187,392 ----a-w C:\WINDOWS\BricoPacks\SysFiles\45_els.dll
+ 2004-08-05 19:00:00 348,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\46_filemgmt.dll
+ 2004-08-05 19:00:00 88,064 ----a-w C:\WINDOWS\BricoPacks\SysFiles\47_Fldrclnr.dll
+ 2004-08-05 19:00:00 386,560 ----a-w C:\WINDOWS\BricoPacks\SysFiles\48_fontext.dll
+ 2004-08-05 19:00:00 336,384 ----a-w C:\WINDOWS\BricoPacks\SysFiles\50_hnetwiz.dll
+ 2004-08-05 19:00:00 146,944 ----a-w C:\WINDOWS\BricoPacks\SysFiles\51_hotplug.dll
+ 2004-08-05 19:00:00 56,320 ----a-w C:\WINDOWS\BricoPacks\SysFiles\52_Icmui.dll
+ 2004-08-05 19:00:00 73,728 ----a-w C:\WINDOWS\BricoPacks\SysFiles\53_Icwdial.dll
+ 2004-08-05 19:00:00 65,536 ----a-w C:\WINDOWS\BricoPacks\SysFiles\54_Icwres.dll
+ 2007-12-07 02:08:32 230,400 ----a-w C:\WINDOWS\BricoPacks\SysFiles\55_ieaksie.dll
+ 2006-11-07 20:03:36 191,488 ----a-w C:\WINDOWS\BricoPacks\SysFiles\56_Iepeers.dll
+ 2007-12-07 02:08:33 44,544 ----a-w C:\WINDOWS\BricoPacks\SysFiles\57_Iernonce.dll
+ 2006-11-07 02:26:42 55,296 ----a-w C:\WINDOWS\BricoPacks\SysFiles\58_Iesetup.dll
+ 2004-08-05 19:00:00 282,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\59_Inetcfg.dll
+ 2004-08-05 19:00:00 921,088 ----a-r C:\WINDOWS\BricoPacks\SysFiles\6_comctl32.dll
+ 2004-08-05 19:00:00 121,856 ----a-w C:\WINDOWS\BricoPacks\SysFiles\60_inetcplc.dll
+ 2004-08-05 19:00:00 157,184 ----a-w C:\WINDOWS\BricoPacks\SysFiles\61_keymgr.dll
+ 2004-08-05 19:00:00 120,320 ----a-w C:\WINDOWS\BricoPacks\SysFiles\62_mdminst.dll
+ 2004-08-05 19:00:00 210,432 ----a-w C:\WINDOWS\BricoPacks\SysFiles\63_mobsync.dll
+ 2004-08-05 19:00:00 156,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\64_Modemui.dll
+ 2004-08-05 19:00:00 216,064 ----a-w C:\WINDOWS\BricoPacks\SysFiles\65_moricons.dll
+ 2007-12-08 05:08:36 3,592,192 ----a-w C:\WINDOWS\BricoPacks\SysFiles\67_mshtml.dll
+ 2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\BricoPacks\SysFiles\68_msi.dll
+ 2004-08-05 19:00:00 51,712 ----a-w C:\WINDOWS\BricoPacks\SysFiles\69_msident.dll
+ 2004-08-05 19:00:00 252,416 ----a-w C:\WINDOWS\BricoPacks\SysFiles\70_msieftp.dll
+ 2004-08-05 19:00:00 2,534,400 ----a-w C:\WINDOWS\BricoPacks\SysFiles\71_MSOERES.DLL
+ 2004-08-05 19:00:00 281,600 ----a-w C:\WINDOWS\BricoPacks\SysFiles\72_mstask.dll
+ 2006-12-11 13:44:01 1,866,240 ----a-w C:\WINDOWS\BricoPacks\SysFiles\73_Mstscax.dll
+ 2004-08-05 19:00:00 90,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\74_mycomput.dll
+ 2004-08-05 19:00:00 91,648 ----a-w C:\WINDOWS\BricoPacks\SysFiles\75_mydocs.dll
+ 2004-08-05 19:00:00 144,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\76_netid.dll
+ 2004-08-05 19:00:00 885,248 ----a-w C:\WINDOWS\BricoPacks\SysFiles\77_netplwiz.dll
+ 2004-08-05 19:00:00 1,723,904 ----a-w C:\WINDOWS\BricoPacks\SysFiles\78_netshell.dll
+ 2004-08-05 19:00:00 251,392 ----a-w C:\WINDOWS\BricoPacks\SysFiles\79_newdev.dll
+ 2004-08-05 19:00:00 1,050,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\8_comctl32.dll
+ 2004-08-05 19:00:00 145,920 ----a-w C:\WINDOWS\BricoPacks\SysFiles\80_ntshrui.dll
+ 2007-12-07 02:08:34 102,912 ----a-w C:\WINDOWS\BricoPacks\SysFiles\81_occache.dll
+ 2004-08-05 19:00:00 172,032 ----a-w C:\WINDOWS\BricoPacks\SysFiles\82_photowiz.dll
+ 2004-08-05 19:00:00 578,560 ----a-w C:\WINDOWS\BricoPacks\SysFiles\83_printui.dll
+ 2004-08-05 19:00:00 685,056 ----a-w C:\WINDOWS\BricoPacks\SysFiles\84_rasdlg.dll
+ 2004-08-05 19:00:00 61,952 ----a-w C:\WINDOWS\BricoPacks\SysFiles\85_remotepg.dll
+ 2004-08-05 19:00:00 55,296 ----a-w C:\WINDOWS\BricoPacks\SysFiles\86_sendmail.dll
+ 2004-08-05 19:00:00 1,003,520 ----a-w C:\WINDOWS\BricoPacks\SysFiles\87_setupapi.dll
+ 2004-08-05 19:00:00 142,336 ----a-w C:\WINDOWS\BricoPacks\SysFiles\88_sfc_os.dll
+ 2004-08-05 19:00:00 572,416 ----a-w C:\WINDOWS\BricoPacks\SysFiles\89_shdoclc.dll
+ 2007-01-04 14:02:16 1,498,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\90_shdocvw.dll
+ 2004-08-05 19:00:00 440,320 ----a-w C:\WINDOWS\BricoPacks\SysFiles\91_shimgvw.dll
+ 2007-01-04 14:02:17 474,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\92_SHLWAPI.DLL
+ 2004-08-05 19:00:00 726,590 ----a-w C:\WINDOWS\BricoPacks\SysFiles\93_srchui.dll
+ 2004-08-05 19:00:00 241,664 ----a-w C:\WINDOWS\BricoPacks\SysFiles\94_srrstr.dll
+ 2004-08-05 19:00:00 138,240 ----a-w C:\WINDOWS\BricoPacks\SysFiles\95_sti_ci.dll
+ 2004-08-05 19:00:00 122,368 ----a-w C:\WINDOWS\BricoPacks\SysFiles\96_stobject.dll
+ 2004-08-05 19:00:00 197,120 ----a-w C:\WINDOWS\BricoPacks\SysFiles\97_syncui.dll
+ 2004-08-05 19:00:00 1,005,056 ----a-w C:\WINDOWS\BricoPacks\SysFiles\98_syssetup.dll
+ 2004-08-05 19:00:00 87,040 ----a-w C:\WINDOWS\BricoPacks\SysFiles\99_tapiui.dll
+ 2008-03-29 13:57:34 219,648 ----a-w C:\WINDOWS\BricoPacks\SysFiles\Ux_uxtheme.dll
+ 2008-03-24 17:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.28\FP_AX_CAB_INSTALLER.exe
+ 2008-03-24 17:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.29\FP_AX_CAB_INSTALLER.exe
- 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2000-08-31 06:00:00 89,504 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 06:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
- 2005-05-27 06:22:01 10,752 ----a-w C:\WINDOWS\hh.exe
+ 2005-05-27 06:22:01 167,936 ----a-w C:\WINDOWS\Hh.exe
+ 2004-08-05 19:00:00 2,589 ----a-w C:\WINDOWS\I386\RUNW32.BAT
+ 2007-12-07 02:08:32 124,928 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll
+ 2007-12-19 22:53:23 347,136 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll
+ 2007-12-07 02:08:32 214,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll
+ 2007-12-07 02:08:32 133,120 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll
+ 2007-12-07 02:08:32 63,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll
+ 2007-12-06 11:02:31 70,656 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe
+ 2007-12-07 02:08:32 153,088 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll
+ 2007-12-07 02:08:32 1,470,464 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll
+ 2007-12-06 04:59:51 161,792 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll
+ 2007-12-07 02:08:32 383,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll
+ 2007-12-07 02:08:32 384,512 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll
+ 2007-12-07 02:08:33 6,066,176 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll
+ 2007-12-07 02:08:33 150,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll
+ 2007-12-07 02:08:33 267,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll
+ 2007-12-06 11:00:58 13,824 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe
+ 2007-12-06 11:03:16 3,110,400 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
+ 2007-12-07 02:08:33 27,648 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll
+ 2007-12-07 02:08:33 459,264 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll
+ 2007-12-07 02:08:33 52,224 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll
+ 2007-12-08 05:08:36 5,864,960 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll
+ 2007-12-07 02:08:34 478,208 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll
+ 2007-12-07 02:08:34 193,024 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll
+ 2007-12-07 02:08:34 671,232 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll
+ 2007-12-07 02:08:34 905,728 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll
+ 2008-01-11 05:36:55 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll
+ 2007-12-07 02:08:34 489,472 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll
+ 2007-12-07 02:08:34 1,643,520 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll
+ 2007-12-07 02:08:34 1,451,008 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll
+ 2007-12-07 02:08:34 2,050,560 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
+ 2008-05-13 08:25:16 32,768 ----a-r C:\WINDOWS\Installer\{716E0306-8318-4364-8B8F-0CC4E9376BAC}\icon.exe
+ 2008-04-25 08:35:21 65,536 ----a-r C:\WINDOWS\Installer\{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}\ARPPRODUCTICON.exe
+ 2008-05-15 01:01:20 2,560 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2008-03-12 10:42:05 34,304 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2008-05-15 01:01:20 34,304 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2008-03-12 10:42:05 8,192 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2008-05-15 01:01:20 8,192 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-03-12 10:42:05 3,584 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2008-05-15 01:01:20 3,584 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2008-03-12 10:42:05 16,384 ----a-r
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.570 [GMT 2:00]
Endroit: C:\Documents and Settings\sabine\Mes documents\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\BM438aa6a1.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aesrboam.ini
C:\WINDOWS\system32\asgmkobl.dll
C:\WINDOWS\system32\bidlowub.dll
C:\WINDOWS\system32\cbgkdrkv.ini
C:\WINDOWS\system32\cKTDKUvw.ini
C:\WINDOWS\system32\cKTDKUvw.ini2
C:\WINDOWS\system32\cnacrmim.ini
C:\WINDOWS\system32\cwvxnjcx.ini
C:\WINDOWS\system32\dchocaud.dll
C:\WINDOWS\system32\dgxerpgh.ini
C:\WINDOWS\system32\dpujivgk.ini
C:\WINDOWS\system32\dsnbfxcn.ini
C:\WINDOWS\system32\eNWwyGgh.ini
C:\WINDOWS\system32\eNWwyGgh.ini2
C:\WINDOWS\system32\fecnvgxq.exe
C:\WINDOWS\system32\fgvxxjyp.dll
C:\WINDOWS\system32\fxsqbebs.ini
C:\WINDOWS\system32\gqtyjdec.ini
C:\WINDOWS\system32\hsvtotgd.exe
C:\WINDOWS\system32\jfqjxfrv.ini
C:\WINDOWS\system32\jjnnbjmj.ini
C:\WINDOWS\system32\jmboohsa.ini
C:\WINDOWS\system32\jvsbnhsy.ini
C:\WINDOWS\system32\kpmkuxgs.ini
C:\WINDOWS\system32\kuxyeyox.ini
C:\WINDOWS\system32\lawhrpea.ini
C:\WINDOWS\system32\lbdyxvtv.dll
C:\WINDOWS\system32\lfmaywau.ini
C:\WINDOWS\system32\lfqfqtbb.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mprhhldh.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mxqfdchj.dll
C:\WINDOWS\system32\oorwflya.dll
C:\WINDOWS\system32\oxpfshxh.ini
C:\WINDOWS\system32\pnraslbb.ini
C:\WINDOWS\system32\pqluulut.ini
C:\WINDOWS\system32\qgxseftd.dll
C:\WINDOWS\system32\qpchvjaa.dll
C:\WINDOWS\system32\qxqsnjvr.ini
C:\WINDOWS\system32\rihifnsc.ini
C:\WINDOWS\system32\tbcvkmfi.exe
C:\WINDOWS\system32\tbeoykfm.ini
C:\WINDOWS\system32\tbshxfeo.ini
C:\WINDOWS\system32\tcmocyyh.ini
C:\WINDOWS\system32\toliepgm.dll
C:\WINDOWS\system32\ukqetrbh.ini
C:\WINDOWS\system32\uorycckp.ini
C:\WINDOWS\system32\wsehkamc.ini
C:\WINDOWS\system32\wslcrlfc.exe
C:\WINDOWS\system32\xamrscqm.ini
C:\WINDOWS\system32\yjjsetrf.ini
C:\WINDOWS\system32\yupbqtyh.exe
C:\WINDOWS\system32\ywsmsubd.ini
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-28 to 2008-05-29 ))))))))))))))))))))))))))))))))))))
.
2008-05-29 13:24 . 2004-07-29 02:23 172,032 --a------ C:\WINDOWS\system32\LameACM.acm
2008-05-29 13:24 . 2004-07-29 02:23 172,032 --a------ C:\lameACM.acm
2008-05-29 13:24 . 2004-08-22 06:48 1,720 --a------ C:\LameACM.inf
2008-05-29 13:24 . 2002-04-07 14:17 401 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-05-29 13:24 . 2002-04-07 14:17 401 --a------ C:\lame_acm.xml
2008-05-20 10:08 . 2008-05-20 10:08 <REP> d-------- C:\WINDOWS\McAfee.com
2008-05-20 09:46 . 2008-03-01 14:58 6,032,384 --a--c--- C:\WINDOWS\system32\dllcache\nsj8.tmp
2008-05-19 17:53 . 2008-05-19 17:53 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-19 14:31 . 2008-05-28 18:10 269 --a------ C:\WINDOWS\wininit.ini
2008-05-19 14:06 . 2008-05-19 14:06 <REP> d-------- C:\Program Files\Lavasoft
2008-05-19 14:06 . 2008-05-19 14:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-19 14:05 . 2008-05-19 14:05 <REP> d-------- C:\Program Files\Trend Micro
2008-05-19 14:05 . 2008-05-19 14:05 <REP> d-------- C:\Documents and Settings\laurent\Application Data\Malwarebytes
2008-05-19 14:02 . 2008-05-29 17:48 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-19 14:02 . 2008-05-19 14:02 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-19 14:02 . 2008-05-29 17:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-19 14:02 . 2008-05-19 14:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-19 14:02 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-19 14:02 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-19 12:01 . 2008-05-29 17:51 <REP> d-------- C:\Program Files\PC Tools AntiVirus
2008-05-19 12:01 . 2008-05-19 12:01 <REP> d-------- C:\Program Files\Fichiers communs\PC Tools
2008-05-19 12:01 . 2008-05-19 12:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-05-19 12:01 . 2007-12-06 15:51 28,568 --a------ C:\WINDOWS\system32\drivers\AVHook.sys
2008-05-19 12:01 . 2007-12-06 15:51 21,912 --a------ C:\WINDOWS\system32\drivers\AVRec.sys
2008-05-19 12:01 . 2008-02-12 10:44 21,904 --a------ C:\WINDOWS\system32\drivers\AVFilter.sys
2008-05-18 20:40 . 2008-05-18 20:40 125,952 --a------ C:\WINDOWS\system32\toliepgm.VIR000
2008-05-17 21:37 . 2008-05-17 21:37 371,712 --a------ C:\WINDOWS\system32\nnnLcCVl.VIR
2008-05-16 09:38 . 2008-05-16 09:46 <REP> d-------- C:\Program Files\AVPersonalPremium
2008-05-13 10:25 . 2008-05-13 16:41 <REP> d-------- C:\Program Files\Larousse
2008-05-09 15:03 . 2008-05-09 15:03 <REP> dr-h----- C:\MSOCache
2008-05-02 20:56 . 2008-05-20 21:16 <REP> d-------- C:\Program Files\Astro Avenger 2
2008-05-02 20:56 . 2008-05-02 20:56 <REP> d-------- C:\Documents and Settings\laurent\Application Data\Sahmon Games
2008-05-01 21:49 . 2008-05-01 21:49 <REP> d-------- C:\WINDOWS\msdownld.tmp
2008-05-01 21:42 . 2008-05-01 21:42 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-01 21:42 . 2008-05-01 21:42 22,328 --a------ C:\Documents and Settings\laurent\Application Data\PnkBstrK.sys
2008-05-01 21:41 . 2008-05-01 21:41 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-01 21:41 . 2008-05-01 21:41 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-01 21:41 . 2008-05-01 21:41 319 --a------ C:\WINDOWS\game.ini
2008-05-01 21:21 . 2008-05-01 21:21 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-05-01 18:40 . 2008-05-01 18:40 <REP> d-------- C:\Program Files\Traction Software
2008-04-29 14:27 . 2008-05-19 22:23 38 --a------ C:\Documents and Settings\laurent\launcher.dat
2008-04-29 14:11 . 2008-04-29 14:11 <REP> d-------- C:\Team17
2008-04-29 14:08 . 1997-08-26 12:06 315,904 --a------ C:\WINDOWS\IsUninst.exe
2008-04-29 14:07 . 2008-04-29 14:09 47,104 --a------ C:\WINDOWS\system32\KMVIDC32.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 16:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-29 15:59 --------- d-----w C:\Documents and Settings\laurent\Application Data\DNA
2008-05-29 13:31 --------- d-----w C:\Program Files\eMule
2008-05-29 11:22 --------- d-----w C:\Program Files\Video Convert Master
2008-05-29 09:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-29 08:47 --------- d-----w C:\Documents and Settings\laurent\Application Data\BitTorrent
2008-05-28 12:33 --------- d-----w C:\Program Files\Jewel Quest Solitaire
2008-05-20 19:18 --------- d-----w C:\Program Files\Kyodai Mahjongg
2008-05-20 14:50 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-19 14:41 --------- d-----w C:\Program Files\Elf Bowling The Last Insult
2008-05-19 14:40 --------- d-----w C:\Program Files\Jewel Quest Solitaire II
2008-05-19 14:39 --------- d-----w C:\Program Files\Micro Application
2008-05-19 14:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-19 13:28 8,192 --sha-w C:\Program Files\Thumbs.db
2008-05-19 10:04 --------- d-----w C:\Documents and Settings\laurent\Application Data\PC Tools
2008-05-18 18:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-05-15 20:51 92,232 ----a-w C:\Documents and Settings\laurent\Application Data\GDIPFONTCACHEV1.DAT
2008-05-13 01:47 --------- d-----w C:\Program Files\BitTorrent
2008-05-02 16:26 3,532 ----a-w C:\drmHeader.bin
2008-04-30 09:05 --------- d-----w C:\Program Files\Mah Jong Quest II
2008-04-30 09:05 --------- d-----w C:\Program Files\Brickshooter Egypt
2008-04-30 09:04 --------- d-----w C:\Program Files\Race Cars The Extreme Rally
2008-04-29 12:16 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-28 16:22 --------- d-----w C:\Program Files\Mad Cars
2008-04-25 08:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-04-25 08:29 --------- d-----w C:\Program Files\Bonjour
2008-04-23 14:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-23 14:22 --------- d-----w C:\Program Files\Fichiers communs\Macrovision Shared
2008-04-22 18:22 --------- d-----w C:\Documents and Settings\laurent\Application Data\gtk-2.0
2008-04-22 16:07 --------- d-----w C:\Program Files\ACD Systems
2008-04-20 18:56 --------- d-----w C:\Program Files\Totem Quest
2008-04-20 16:39 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-04-11 19:14 --------- d-----w C:\Program Files\Big Kahuna Reef
2008-04-10 06:19 --------- d-----w C:\Program Files\DivX
2008-04-09 09:56 --------- d-----w C:\Program Files\Alcohol Soft
2008-04-09 08:42 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-04-06 09:37 3,699,424 ----atw C:\WINDOWS\DXM1F1.tmp
2008-04-06 07:58 --------- d-----w C:\Program Files\D-Tools
2008-04-05 19:34 --------- d-----w C:\Program Files\Netlog 24
2008-04-05 14:54 --------- d-----w C:\Documents and Settings\laurent\Application Data\Windows Live Writer
2008-04-05 14:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-02 10:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2008-03-29 20:58 --------- d-----w C:\Program Files\LClock
2008-03-29 20:58 --------- d-----w C:\Program Files\iColorFolder
2008-03-29 20:56 --------- d-----w C:\Program Files\CursorXP
2008-03-29 20:49 --------- d-----w C:\Program Files\Act 3d
2008-03-29 20:47 79,435 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-03-29 20:47 2,355 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-03-29 20:47 --------- d-----w C:\Program Files\UberIcon
2008-03-29 20:47 --------- d-----w C:\Program Files\Stardock
2008-03-28 14:55 --------- d-----w C:\Documents and Settings\laurent\Application Data\iWin
2008-03-16 15:20 98,304 ----a-w C:\WINDOWS\DUMP3345.tmp
2008-03-02 14:47 0 ----a-w C:\Program Files\temp01
2007-11-03 21:49 47,360 ----a-w C:\Documents and Settings\laurent\Application Data\pcouffin.sys
2007-05-08 19:51 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-02-13 17:56 10,240 --sha-w C:\WINDOWS\rnapxs\rnapxs.dat
2007-11-02 16:04 56 --sh--r C:\WINDOWS\system32\5C84FAE664.sys
2007-11-02 16:04 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2005-03-03 03:20 578048 c34920eb988ce98910bd6b0417f334eb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 17:50 579072 4d88aaf39adabfe45958ea1384e2c4ff C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-05 21:00 578048 e46fb493e3b33704f0715020cf52106b C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-03 03:10 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2007-03-08 17:37 572928 aecdb362e13a761bb7494dcdffdda575 C:\WINDOWS\system32\user32.dll
2007-03-08 17:37 572928 aecdb362e13a761bb7494dcdffdda575 C:\WINDOWS\system32\dllcache\user32.dll
2007-06-13 15:22 4457984 35478020b7c8b03a95a6e896e4857cf5 C:\WINDOWS\explorer.exe
2007-06-13 15:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-05 21:00 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 15:22 4457984 35478020b7c8b03a95a6e896e4857cf5 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-03-19_11.49.33.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-20 07:56:50 1,846,016 ----a-w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll
+ 2008-02-20 05:20:23 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:50:24 45,568 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\updspapi.dll
+ 2008-03-01 12:34:26 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\advpack.dll
+ 2008-03-01 12:34:26 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtmsft.dll
+ 2008-03-01 12:34:26 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtrans.dll
+ 2008-03-01 12:34:27 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\extmgr.dll
+ 2008-03-01 12:34:27 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\icardie.dll
+ 2008-02-22 09:39:56 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ie4uinit.exe
+ 2008-03-01 12:34:27 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakeng.dll
+ 2008-03-01 12:34:27 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieaksie.dll
+ 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dat
+ 2008-03-01 12:34:27 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dll
+ 2008-03-01 12:34:27 388,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iedkcs32.dll
+ 2008-03-01 12:34:29 6,067,712 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieframe.dll
+ 2008-03-01 12:34:29 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iernonce.dll
+ 2008-03-01 12:34:29 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iertutil.dll
+ 2008-02-22 09:39:56 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieudinit.exe
+ 2008-02-22 09:40:22 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
+ 2008-03-01 12:34:30 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\jsproxy.dll
+ 2008-03-01 12:34:30 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeeds.dll
+ 2008-03-01 12:34:30 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeedsbs.dll
+ 2008-03-01 12:34:32 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
+ 2008-03-01 12:34:32 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtmled.dll
+ 2008-03-01 12:34:32 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msrating.dll
+ 2008-03-01 12:34:32 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mstime.dll
+ 2008-03-01 12:34:32 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\occache.dll
+ 2008-03-01 12:34:32 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\pngfilt.dll
+ 2008-03-01 12:34:32 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\url.dll
+ 2008-03-01 12:34:33 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\urlmon.dll
+ 2008-03-01 12:34:33 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\webcheck.dll
+ 2008-03-01 12:34:33 827,392 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\updspapi.dll
+ 2008-02-20 06:52:42 282,624 ----a-w C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\updspapi.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\update.exe
+ 2007-03-06 01:35:47 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\updspapi.dll
+ 2008-01-23 04:56:21 554,008 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\dao360.dll
+ 2007-12-10 12:41:11 518,944 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexch40.dll
+ 2007-12-10 12:41:11 326,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
+ 2007-12-10 12:41:11 1,516,568 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjet40.dll
+ 2007-12-10 12:41:11 355,112 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
+ 2008-03-25 06:56:31 194,144 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjint40.dll
+ 2007-12-10 12:41:12 60,192 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjter40.dll
+ 2007-12-10 12:41:12 248,608 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
+ 2007-12-10 12:41:12 219,936 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msltus40.dll
+ 2007-12-10 12:41:12 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
+ 2007-12-10 12:41:13 432,928 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
+ 2007-12-10 12:41:13 322,336 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
+ 2007-12-10 12:41:13 559,904 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
+ 2007-12-10 12:41:13 264,992 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mstext40.dll
+ 2007-12-10 12:41:13 838,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
+ 2007-11-01 05:15:27 621,344 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
+ 2007-12-10 12:41:14 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\updspapi.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\updspapi.dll
+ 2007-03-08 15:33:58 1,843,712 -c----w C:\WINDOWS\$NtUninstallKB941693$\win32k.sys
+ 2006-06-26 17:41:32 148,480 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsapi.dll
+ 2004-08-05 19:00:00 45,568 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsrslvr.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\updspapi.dll
+ 2007-06-19 13:32:25 282,112 -c----w C:\WINDOWS\$NtUninstallKB948590$\gdi32.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\updspapi.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe
+ 2007-03-06 01:35:47 394,976 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\updspapi.dll
- 2008-02-23 13:46:41 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-05-01 19:43:41 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-02-23 13:46:41 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-05-01 19:43:41 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-02-23 13:46:42 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-05-01 19:43:42 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-02-23 13:46:36 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:34 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:36 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:35 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:37 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:35 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:38 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:36 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:38 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:37 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:39 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:37 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:39 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:38 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:39 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:39 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:40 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:39 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:42 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-01 19:43:42 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-23 13:46:42 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-05-01 19:43:43 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-02-23 13:46:43 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-05-01 19:43:43 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-02-23 13:46:43 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-05-01 19:43:44 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-02-23 13:46:43 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-05-01 19:43:44 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-02-23 13:46:40 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-05-01 19:43:40 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-05-29 16:00:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-09-29 20:16:02 789,576 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\cursorxp_free_G3o.exe
+ 2005-08-22 17:19:54 94,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Pack It!.exe
+ 2004-08-05 19:00:00 542,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\100_themeui.dll
+ 2004-08-05 19:00:00 1,273,344 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\101_upnpui.dll
+ 2007-12-07 02:08:34 489,472 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\102_url.dll
+ 2007-12-07 02:08:34 1,643,520 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\103_Urlmon.dll
+ 2007-03-08 15:37:50 572,928 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\104_user32.dll
+ 2004-08-05 19:00:00 2,722,304 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\105_wab32res.dll
+ 2004-08-05 19:00:00 172,032 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\106_Wabfind.dll
+ 2007-12-07 02:08:34 1,451,008 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\107_webcheck.dll
+ 2004-08-05 19:00:00 571,392 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\108_wiadefui.dll
+ 2004-08-05 19:00:00 2,117,120 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\109_wiashext.dll
+ 2007-12-07 02:08:34 2,050,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\110_Wininet.dll
+ 2004-08-05 19:00:00 910,336 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\111_Winntbbu.dll
+ 2007-03-17 13:44:47 431,616 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\112_winsrv.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\114_wuaueng.dll
+ 2004-08-05 19:00:00 11,538,432 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\115_xpsp2res.dll
+ 2004-08-05 19:00:00 1,474,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\116_zipfldr.dll
+ 2004-08-05 19:00:00 650,240 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\117_accwiz.exe
+ 2004-08-05 19:00:00 198,144 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\118_ahui.exe
+ 2004-08-05 19:00:00 215,040 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\119_calc.exe
+ 2004-08-05 19:00:00 164,352 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\120_charmap.exe
+ 2004-08-05 19:00:00 467,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\121_cleanmgr.exe
+ 2004-08-05 19:00:00 501,248 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\122_cmd.exe
+ 2004-08-05 19:00:00 314,368 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\123_Drwtsn32.exe
+ 2007-06-13 13:22:28 4,457,984 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\124_explorer.exe
+ 2004-08-05 19:00:00 220,672 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\125_Grpconv.exe
+ 2004-08-05 19:00:00 862,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\126_helpctr.exe
+ 2005-05-27 06:22:01 167,936 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\127_Hh.exe
+ 2004-08-05 19:00:00 111,616 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\128_hypertrm.exe
+ 2004-08-05 19:00:00 452,096 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\129_icwconn1.exe
+ 2004-08-05 19:00:00 249,856 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\130_icwconn2.exe
+ 2007-12-06 11:03:16 3,110,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\131_iexplore.exe
+ 2004-08-05 19:00:00 506,368 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\132_logon.scr
+ 2006-10-04 13:32:58 173,568 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\133_magnify.exe
+ 2004-08-05 19:00:00 386,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\134_migload.exe
+ 2004-08-05 19:00:00 153,600 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\135_migpwd.exe
+ 2004-08-05 19:00:00 1,328,128 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\136_migwiz.exe
+ 2004-08-05 19:00:00 583,168 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\137_mobsync.exe
+ 2004-08-05 19:00:00 3,691,520 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\138_moviemk.exe
+ 2004-08-05 19:00:00 321,536 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\139_msconfig.exe
+ 2004-08-05 19:00:00 481,280 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\140_msimn.exe
+ 2004-08-05 19:00:00 179,200 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\141_msinfo32.exe
+ 2004-08-05 19:00:00 166,912 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\142_msoobe.exe
+ 2004-08-05 19:00:00 543,232 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\143_mspaint.exe
+ 2006-11-07 08:06:47 2,462,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\144_mstsc.exe
+ 2006-10-04 13:32:55 194,048 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\145_narrator.exe
+ 2004-08-05 19:00:00 152,064 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\146_notepad.exe
+ 2004-08-05 19:00:00 140,288 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\147_notiflag.exe
+ 2004-08-05 19:00:00 180,224 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\149_odbcad32.exe
+ 2004-08-05 19:00:00 490,496 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\150_Oemig50.exe
+ 2004-08-05 19:00:00 151,552 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\151_oobebaln.exe
+ 2006-10-04 13:32:58 275,456 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\152_osk.exe
+ 2004-08-05 19:00:00 197,120 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\153_rasphone.exe
+ 2004-08-05 19:00:00 180,224 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\154_rcimlby.exe
+ 2004-08-05 19:00:00 1,063,936 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\155_regedit.exe
+ 2004-08-05 19:00:00 531,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\156_rstrui.exe
+ 2004-08-05 19:00:00 220,160 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\157_rtcshare.exe
+ 2004-08-05 19:00:00 426,496 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\158_sndrec32.exe
+ 2004-08-05 19:00:00 785,408 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\159_sndvol32.exe
+ 2004-08-05 19:00:00 149,504 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\160_syncapp.exe
+ 2004-08-05 19:00:00 531,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\161_sysocmgr.exe
+ 2004-08-05 19:00:00 633,344 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\162_taskmgr.exe
+ 2004-08-05 19:00:00 484,352 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\163_tourstart.exe
+ 2006-10-04 13:32:57 188,416 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\164_utilman.exe
+ 2004-08-05 19:00:00 184,832 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\165_wab.exe
+ 2004-08-05 19:00:00 1,975,808 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\166_wiaacmgr.exe
+ 2004-08-05 19:00:00 771,584 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\167_Winhlp32.exe
+ 2004-08-05 19:00:00 670,208 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\168_wordpad.exe
+ 2004-08-05 19:00:00 171,008 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\169_wpabaln.exe
+ 2007-07-30 17:19:16 215,384 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\170_wuauclt.exe
+ 2004-08-05 19:00:00 111,616 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\171_Write.exe
+ 2004-08-05 19:00:00 168,960 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\172_wupdmgr.exe
+ 2007-10-25 16:43:25 9,677,824 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\185_shell32.dll
+ 2004-08-05 19:00:00 1,503,744 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\186_msgina.dll
+ 2006-10-18 20:47:08 1,254,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\187_Audiodev.dll
+ 2006-11-03 09:03:34 9,638,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\188_wmploc.dll
+ 2006-11-03 08:59:00 178,688 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\189_wmplayer.exe
+ 2004-08-05 19:00:00 3,926,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\198_logonui.exe
+ 2004-08-05 19:00:00 641,024 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\28_Acctres.dll
+ 2007-01-04 14:01:53 1,345,536 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\30_Browseui.dll
+ 2004-08-05 19:00:00 325,120 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\31_cabview.dll
+ 2007-01-04 14:01:54 1,163,776 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\32_cdfview.dll
+ 2004-08-05 19:00:00 614,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\33_cmdial32.dll
+ 2004-08-05 19:00:00 867,328 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\34_cmprops.dll
+ 2004-08-05 19:00:00 342,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\35_Comdlg32.dll
+ 2004-08-05 19:00:00 404,992 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\36_compatui.dll
+ 2004-08-05 19:00:00 851,968 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\37_comres.dll
+ 2004-08-05 19:00:00 205,312 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\38_console.dll
+ 2004-08-05 19:00:00 326,656 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\39_credui.dll
+ 2004-08-05 19:00:00 1,597,440 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\40_cscui.dll
+ 2004-08-05 19:00:00 99,328 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\41_Deskadp.dll
+ 2004-08-05 19:00:00 178,176 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\42_Deskmon.dll
+ 2004-08-05 19:00:00 180,224 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\43_Deskperf.dll
+ 2004-08-05 19:00:00 724,480 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\44_devmgr.dll
+ 2004-08-05 19:00:00 348,672 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\45_els.dll
+ 2004-08-05 19:00:00 704,512 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\46_filemgmt.dll
+ 2004-08-05 19:00:00 226,304 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\47_Fldrclnr.dll
+ 2004-08-05 19:00:00 1,352,704 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\48_fontext.dll
+ 2004-08-05 19:00:00 1,334,272 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\50_hnetwiz.dll
+ 2004-08-05 19:00:00 507,904 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\51_hotplug.dll
+ 2004-08-05 19:00:00 268,288 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\52_Icmui.dll
+ 2004-08-05 19:00:00 397,312 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\53_Icwdial.dll
+ 2004-08-05 19:00:00 229,376 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\54_Icwres.dll
+ 2007-12-07 02:08:32 1,470,464 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\55_ieaksie.dll
+ 2006-11-07 20:03:36 340,480 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\56_Iepeers.dll
+ 2007-12-07 02:08:33 150,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\57_Iernonce.dll
+ 2006-11-07 02:26:42 206,848 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\58_Iesetup.dll
+ 2004-08-05 19:00:00 471,040 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\59_Inetcfg.dll
+ 2004-08-05 19:00:00 1,320,960 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\6_comctl32.dll
+ 2004-08-05 19:00:00 2,209,280 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\60_inetcplc.dll
+ 2004-08-05 19:00:00 717,312 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\61_keymgr.dll
+ 2004-08-05 19:00:00 463,872 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\62_mdminst.dll
+ 2004-08-05 19:00:00 1,100,288 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\63_mobsync.dll
+ 2004-08-05 19:00:00 481,792 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\64_Modemui.dll
+ 2004-08-05 19:00:00 345,088 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\65_moricons.dll
+ 2007-12-08 05:08:36 5,864,960 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\67_mshtml.dll
+ 2007-04-18 16:14:18 3,180,544 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\68_msi.dll
+ 2004-08-05 19:00:00 212,992 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\69_msident.dll
+ 2004-08-05 19:00:00 1,382,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\70_msieftp.dll
+ 2004-08-05 19:00:00 4,833,792 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\71_MSOERES.DLL
+ 2004-08-05 19:00:00 838,144 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\72_mstask.dll
+ 2006-12-11 13:44:01 1,973,248 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\73_Mstscax.dll
+ 2004-08-05 19:00:00 785,920 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\74_mycomput.dll
+ 2004-08-05 19:00:00 354,816 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\75_mydocs.dll
+ 2004-08-05 19:00:00 383,488 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\76_netid.dll
+ 2004-08-05 19:00:00 3,534,848 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\77_netplwiz.dll
+ 2004-08-05 19:00:00 7,938,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\78_netshell.dll
+ 2004-08-05 19:00:00 1,475,072 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\79_newdev.dll
+ 2004-08-05 19:00:00 1,450,496 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\8_comctl32.dll
+ 2004-08-05 19:00:00 661,504 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\80_ntshrui.dll
+ 2007-12-07 02:08:34 905,728 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\81_occache.dll
+ 2004-08-05 19:00:00 390,656 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\82_photowiz.dll
+ 2004-08-05 19:00:00 1,474,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\83_printui.dll
+ 2004-08-05 19:00:00 2,534,400 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\84_rasdlg.dll
+ 2004-08-05 19:00:00 200,704 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\85_remotepg.dll
+ 2004-08-05 19:00:00 115,712 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\86_sendmail.dll
+ 2004-08-05 19:00:00 1,281,024 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\87_setupapi.dll
+ 2004-08-05 19:00:00 293,888 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\88_sfc_os.dll
+ 2004-08-05 19:00:00 1,946,624 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\89_shdoclc.dll
+ 2007-01-04 14:02:16 4,751,360 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\90_shdocvw.dll
+ 2004-08-05 19:00:00 1,137,664 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\91_shimgvw.dll
+ 2007-01-04 14:02:17 633,344 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\92_SHLWAPI.DLL
+ 2004-08-05 19:00:00 3,271,230 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\93_srchui.dll
+ 2004-08-05 19:00:00 406,528 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\94_srrstr.dll
+ 2004-08-05 19:00:00 678,912 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\95_sti_ci.dll
+ 2004-08-05 19:00:00 607,232 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\96_stobject.dll
+ 2004-08-05 19:00:00 333,824 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\97_syncui.dll
+ 2004-08-05 19:00:00 3,299,328 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\98_syssetup.dll
+ 2004-08-05 19:00:00 481,792 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\99_tapiui.dll
+ 2008-03-29 13:57:34 219,648 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\PackFiles\Ux_uxtheme.dll
+ 2008-03-29 20:47:39 244,459 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Remove.exe
+ 2007-12-07 10:40:08 15,310 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\173_logonui.exe\27.bin
+ 2007-12-07 10:37:22 2,228 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\1.bin
+ 2007-12-07 10:37:22 2,511 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\10.bin
+ 2007-12-07 10:37:22 2,511 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\11.bin
+ 2007-12-07 10:37:22 3,637 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\2.bin
+ 2007-12-07 10:37:22 3,643 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\3.bin
+ 2007-12-07 10:37:22 4,560 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\4.bin
+ 2007-12-07 10:37:22 4,901 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\5.bin
+ 2007-12-07 10:37:22 4,674 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\6.bin
+ 2007-12-07 10:37:22 3,570 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\7.bin
+ 2007-12-07 10:37:22 3,567 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\8.bin
+ 2007-12-07 10:37:22 3,562 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResFiles\21_wscui.cpl\9.bin
+ 2002-03-24 19:23:38 881,664 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\ResHacker\ResHacker.exe
+ 2007-12-07 10:40:10 246,594 ----a-w C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Update.exe
+ 2004-08-05 19:00:00 391,168 ----a-w C:\WINDOWS\BricoPacks\SysFiles\100_themeui.dll
+ 2004-08-05 19:00:00 240,128 ----a-w C:\WINDOWS\BricoPacks\SysFiles\101_upnpui.dll
+ 2007-12-07 02:08:34 105,984 ----a-w C:\WINDOWS\BricoPacks\SysFiles\102_url.dll
+ 2007-12-07 02:08:34 1,159,680 ----a-w C:\WINDOWS\BricoPacks\SysFiles\103_Urlmon.dll
+ 2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\BricoPacks\SysFiles\104_user32.dll
+ 2004-08-05 19:00:00 263,168 ----a-w C:\WINDOWS\BricoPacks\SysFiles\105_wab32res.dll
+ 2004-08-05 19:00:00 32,768 ----a-w C:\WINDOWS\BricoPacks\SysFiles\106_Wabfind.dll
+ 2007-12-07 02:08:34 233,472 ----a-w C:\WINDOWS\BricoPacks\SysFiles\107_webcheck.dll
+ 2004-08-05 19:00:00 465,920 ----a-w C:\WINDOWS\BricoPacks\SysFiles\108_wiadefui.dll
+ 2004-08-05 19:00:00 594,432 ----a-w C:\WINDOWS\BricoPacks\SysFiles\109_wiashext.dll
+ 2007-12-07 02:08:34 824,832 ----a-w C:\WINDOWS\BricoPacks\SysFiles\110_Wininet.dll
+ 2004-08-05 19:00:00 773,632 ----a-w C:\WINDOWS\BricoPacks\SysFiles\111_Winntbbu.dll
+ 2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\BricoPacks\SysFiles\112_winsrv.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\BricoPacks\SysFiles\114_wuaueng.dll
+ 2004-08-05 19:00:00 2,986,496 ----a-w C:\WINDOWS\BricoPacks\SysFiles\115_xpsp2res.dll
+ 2004-08-05 19:00:00 340,480 ----a-w C:\WINDOWS\BricoPacks\SysFiles\116_zipfldr.dll
+ 2004-08-05 19:00:00 189,952 ----a-w C:\WINDOWS\BricoPacks\SysFiles\117_accwiz.exe
+ 2004-08-05 19:00:00 98,304 ----a-w C:\WINDOWS\BricoPacks\SysFiles\118_ahui.exe
+ 2004-08-05 19:00:00 115,200 ----a-w C:\WINDOWS\BricoPacks\SysFiles\119_calc.exe
+ 2004-08-05 19:00:00 80,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\120_charmap.exe
+ 2004-08-05 19:00:00 65,536 ----a-w C:\WINDOWS\BricoPacks\SysFiles\121_cleanmgr.exe
+ 2004-08-05 19:00:00 400,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\122_cmd.exe
+ 2004-08-05 19:00:00 47,104 ----a-w C:\WINDOWS\BricoPacks\SysFiles\123_Drwtsn32.exe
+ 2007-06-13 13:22:28 1,037,312 ----a-w C:\WINDOWS\BricoPacks\SysFiles\124_explorer.exe
+ 2004-08-05 19:00:00 39,424 ----a-w C:\WINDOWS\BricoPacks\SysFiles\125_Grpconv.exe
+ 2004-08-05 19:00:00 768,512 ----a-w C:\WINDOWS\BricoPacks\SysFiles\126_helpctr.exe
+ 2005-05-27 06:22:01 10,752 ----a-w C:\WINDOWS\BricoPacks\SysFiles\127_Hh.exe
+ 2004-08-05 19:00:00 28,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\128_hypertrm.exe
+ 2004-08-05 19:00:00 218,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\129_icwconn1.exe
+ 2004-08-05 19:00:00 86,016 ----a-w C:\WINDOWS\BricoPacks\SysFiles\130_icwconn2.exe
+ 2007-12-06 11:03:16 625,664 ----a-w C:\WINDOWS\BricoPacks\SysFiles\131_iexplore.exe
+ 2004-08-05 19:00:00 221,696 ----a-w C:\WINDOWS\BricoPacks\SysFiles\132_logon.scr
+ 2006-10-04 13:32:58 73,216 ----a-w C:\WINDOWS\BricoPacks\SysFiles\133_magnify.exe
+ 2004-08-05 19:00:00 103,936 ----a-w C:\WINDOWS\BricoPacks\SysFiles\134_migload.exe
+ 2004-08-05 19:00:00 52,736 ----a-w C:\WINDOWS\BricoPacks\SysFiles\135_migpwd.exe
+ 2004-08-05 19:00:00 246,784 ----a-w C:\WINDOWS\BricoPacks\SysFiles\136_migwiz.exe
+ 2004-08-05 19:00:00 144,384 ----a-w C:\WINDOWS\BricoPacks\SysFiles\137_mobsync.exe
+ 2004-08-05 19:00:00 3,555,328 ----a-w C:\WINDOWS\BricoPacks\SysFiles\138_moviemk.exe
+ 2004-08-05 19:00:00 160,768 ----a-w C:\WINDOWS\BricoPacks\SysFiles\139_msconfig.exe
+ 2004-08-05 19:00:00 60,416 ----a-w C:\WINDOWS\BricoPacks\SysFiles\140_msimn.exe
+ 2004-08-05 19:00:00 40,448 ----a-w C:\WINDOWS\BricoPacks\SysFiles\141_msinfo32.exe
+ 2004-08-05 19:00:00 28,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\142_msoobe.exe
+ 2004-08-05 19:00:00 347,648 ----a-w C:\WINDOWS\BricoPacks\SysFiles\143_mspaint.exe
+ 2006-11-07 08:06:47 600,576 ----a-w C:\WINDOWS\BricoPacks\SysFiles\144_mstsc.exe
+ 2006-10-04 13:32:55 55,296 ----a-w C:\WINDOWS\BricoPacks\SysFiles\145_narrator.exe
+ 2004-08-05 19:00:00 70,656 ----a-w C:\WINDOWS\BricoPacks\SysFiles\146_notepad.exe
+ 2004-08-05 19:00:00 35,328 ----a-w C:\WINDOWS\BricoPacks\SysFiles\147_notiflag.exe
+ 2004-08-05 19:00:00 32,768 ----a-w C:\WINDOWS\BricoPacks\SysFiles\149_odbcad32.exe
+ 2004-08-05 19:00:00 60,928 ----a-w C:\WINDOWS\BricoPacks\SysFiles\150_Oemig50.exe
+ 2004-08-05 19:00:00 51,712 ----a-w C:\WINDOWS\BricoPacks\SysFiles\151_oobebaln.exe
+ 2006-10-04 13:32:58 216,576 ----a-w C:\WINDOWS\BricoPacks\SysFiles\152_osk.exe
+ 2004-08-05 19:00:00 57,344 ----a-w C:\WINDOWS\BricoPacks\SysFiles\153_rasphone.exe
+ 2004-08-05 19:00:00 35,840 ----a-w C:\WINDOWS\BricoPacks\SysFiles\154_rcimlby.exe
+ 2004-08-05 19:00:00 153,088 ----a-w C:\WINDOWS\BricoPacks\SysFiles\155_regedit.exe
+ 2004-08-05 19:00:00 384,512 ----a-w C:\WINDOWS\BricoPacks\SysFiles\156_rstrui.exe
+ 2004-08-05 19:00:00 78,336 ----a-w C:\WINDOWS\BricoPacks\SysFiles\157_rtcshare.exe
+ 2004-08-05 19:00:00 133,120 ----a-w C:\WINDOWS\BricoPacks\SysFiles\158_sndrec32.exe
+ 2004-08-05 19:00:00 139,264 ----a-w C:\WINDOWS\BricoPacks\SysFiles\159_sndvol32.exe
+ 2004-08-05 19:00:00 51,200 ----a-w C:\WINDOWS\BricoPacks\SysFiles\160_syncapp.exe
+ 2004-08-05 19:00:00 107,520 ----a-w C:\WINDOWS\BricoPacks\SysFiles\161_sysocmgr.exe
+ 2004-08-05 19:00:00 143,360 ----a-w C:\WINDOWS\BricoPacks\SysFiles\162_taskmgr.exe
+ 2004-08-05 19:00:00 347,136 ----a-w C:\WINDOWS\BricoPacks\SysFiles\163_tourstart.exe
+ 2006-10-04 13:32:57 50,176 ----a-w C:\WINDOWS\BricoPacks\SysFiles\164_utilman.exe
+ 2004-08-05 19:00:00 46,080 ----a-w C:\WINDOWS\BricoPacks\SysFiles\165_wab.exe
+ 2004-08-05 19:00:00 438,784 ----a-w C:\WINDOWS\BricoPacks\SysFiles\166_wiaacmgr.exe
+ 2004-08-05 19:00:00 288,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\167_Winhlp32.exe
+ 2004-08-05 19:00:00 218,112 ----a-w C:\WINDOWS\BricoPacks\SysFiles\168_wordpad.exe
+ 2004-08-05 19:00:00 32,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\169_wpabaln.exe
+ 2007-07-30 17:19:16 53,080 ----a-w C:\WINDOWS\BricoPacks\SysFiles\170_wuauclt.exe
+ 2004-08-05 19:00:00 5,632 ----a-w C:\WINDOWS\BricoPacks\SysFiles\171_Write.exe
+ 2004-08-05 19:00:00 32,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\172_wupdmgr.exe
+ 2007-10-25 16:43:25 8,516,608 ----a-w C:\WINDOWS\BricoPacks\SysFiles\185_shell32.dll
+ 2004-08-05 19:00:00 1,004,032 ----a-w C:\WINDOWS\BricoPacks\SysFiles\186_msgina.dll
+ 2006-10-18 20:47:08 276,992 ----a-w C:\WINDOWS\BricoPacks\SysFiles\187_Audiodev.dll
+ 2006-11-03 09:03:34 8,292,352 ----a-w C:\WINDOWS\BricoPacks\SysFiles\188_wmploc.dll
+ 2006-11-03 08:59:00 64,000 ----a-w C:\WINDOWS\BricoPacks\SysFiles\189_wmplayer.exe
+ 2004-08-05 19:00:00 515,584 ----a-w C:\WINDOWS\BricoPacks\SysFiles\198_logonui.exe
+ 2004-06-18 12:07:33 656,542 ----a-w C:\WINDOWS\BricoPacks\SysFiles\218_icolorfolder.dll
+ 2004-08-05 19:00:00 72,192 ----a-w C:\WINDOWS\BricoPacks\SysFiles\28_Acctres.dll
+ 2007-01-04 14:01:53 1,023,488 ----a-w C:\WINDOWS\BricoPacks\SysFiles\30_Browseui.dll
+ 2004-08-05 19:00:00 85,504 ----a-w C:\WINDOWS\BricoPacks\SysFiles\31_cabview.dll
+ 2007-01-04 14:01:54 152,064 ----a-w C:\WINDOWS\BricoPacks\SysFiles\32_cdfview.dll
+ 2004-08-05 19:00:00 352,256 ----a-w C:\WINDOWS\BricoPacks\SysFiles\33_cmdial32.dll
+ 2004-08-05 19:00:00 191,488 ----a-w C:\WINDOWS\BricoPacks\SysFiles\34_cmprops.dll
+ 2004-08-05 19:00:00 281,088 ----a-w C:\WINDOWS\BricoPacks\SysFiles\35_Comdlg32.dll
+ 2004-08-05 19:00:00 253,440 ----a-w C:\WINDOWS\BricoPacks\SysFiles\36_compatui.dll
+ 2004-08-05 19:00:00 851,968 ----a-w C:\WINDOWS\BricoPacks\SysFiles\37_comres.dll
+ 2004-08-05 19:00:00 67,072 ----a-w C:\WINDOWS\BricoPacks\SysFiles\38_console.dll
+ 2004-08-05 19:00:00 165,888 ----a-w C:\WINDOWS\BricoPacks\SysFiles\39_credui.dll
+ 2004-08-05 19:00:00 337,920 ----a-w C:\WINDOWS\BricoPacks\SysFiles\40_cscui.dll
+ 2004-08-05 19:00:00 16,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\41_Deskadp.dll
+ 2004-08-05 19:00:00 16,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\42_Deskmon.dll
+ 2004-08-05 19:00:00 18,944 ----a-w C:\WINDOWS\BricoPacks\SysFiles\43_Deskperf.dll
+ 2004-08-05 19:00:00 290,816 ----a-w C:\WINDOWS\BricoPacks\SysFiles\44_devmgr.dll
+ 2004-08-05 19:00:00 187,392 ----a-w C:\WINDOWS\BricoPacks\SysFiles\45_els.dll
+ 2004-08-05 19:00:00 348,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\46_filemgmt.dll
+ 2004-08-05 19:00:00 88,064 ----a-w C:\WINDOWS\BricoPacks\SysFiles\47_Fldrclnr.dll
+ 2004-08-05 19:00:00 386,560 ----a-w C:\WINDOWS\BricoPacks\SysFiles\48_fontext.dll
+ 2004-08-05 19:00:00 336,384 ----a-w C:\WINDOWS\BricoPacks\SysFiles\50_hnetwiz.dll
+ 2004-08-05 19:00:00 146,944 ----a-w C:\WINDOWS\BricoPacks\SysFiles\51_hotplug.dll
+ 2004-08-05 19:00:00 56,320 ----a-w C:\WINDOWS\BricoPacks\SysFiles\52_Icmui.dll
+ 2004-08-05 19:00:00 73,728 ----a-w C:\WINDOWS\BricoPacks\SysFiles\53_Icwdial.dll
+ 2004-08-05 19:00:00 65,536 ----a-w C:\WINDOWS\BricoPacks\SysFiles\54_Icwres.dll
+ 2007-12-07 02:08:32 230,400 ----a-w C:\WINDOWS\BricoPacks\SysFiles\55_ieaksie.dll
+ 2006-11-07 20:03:36 191,488 ----a-w C:\WINDOWS\BricoPacks\SysFiles\56_Iepeers.dll
+ 2007-12-07 02:08:33 44,544 ----a-w C:\WINDOWS\BricoPacks\SysFiles\57_Iernonce.dll
+ 2006-11-07 02:26:42 55,296 ----a-w C:\WINDOWS\BricoPacks\SysFiles\58_Iesetup.dll
+ 2004-08-05 19:00:00 282,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\59_Inetcfg.dll
+ 2004-08-05 19:00:00 921,088 ----a-r C:\WINDOWS\BricoPacks\SysFiles\6_comctl32.dll
+ 2004-08-05 19:00:00 121,856 ----a-w C:\WINDOWS\BricoPacks\SysFiles\60_inetcplc.dll
+ 2004-08-05 19:00:00 157,184 ----a-w C:\WINDOWS\BricoPacks\SysFiles\61_keymgr.dll
+ 2004-08-05 19:00:00 120,320 ----a-w C:\WINDOWS\BricoPacks\SysFiles\62_mdminst.dll
+ 2004-08-05 19:00:00 210,432 ----a-w C:\WINDOWS\BricoPacks\SysFiles\63_mobsync.dll
+ 2004-08-05 19:00:00 156,160 ----a-w C:\WINDOWS\BricoPacks\SysFiles\64_Modemui.dll
+ 2004-08-05 19:00:00 216,064 ----a-w C:\WINDOWS\BricoPacks\SysFiles\65_moricons.dll
+ 2007-12-08 05:08:36 3,592,192 ----a-w C:\WINDOWS\BricoPacks\SysFiles\67_mshtml.dll
+ 2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\BricoPacks\SysFiles\68_msi.dll
+ 2004-08-05 19:00:00 51,712 ----a-w C:\WINDOWS\BricoPacks\SysFiles\69_msident.dll
+ 2004-08-05 19:00:00 252,416 ----a-w C:\WINDOWS\BricoPacks\SysFiles\70_msieftp.dll
+ 2004-08-05 19:00:00 2,534,400 ----a-w C:\WINDOWS\BricoPacks\SysFiles\71_MSOERES.DLL
+ 2004-08-05 19:00:00 281,600 ----a-w C:\WINDOWS\BricoPacks\SysFiles\72_mstask.dll
+ 2006-12-11 13:44:01 1,866,240 ----a-w C:\WINDOWS\BricoPacks\SysFiles\73_Mstscax.dll
+ 2004-08-05 19:00:00 90,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\74_mycomput.dll
+ 2004-08-05 19:00:00 91,648 ----a-w C:\WINDOWS\BricoPacks\SysFiles\75_mydocs.dll
+ 2004-08-05 19:00:00 144,896 ----a-w C:\WINDOWS\BricoPacks\SysFiles\76_netid.dll
+ 2004-08-05 19:00:00 885,248 ----a-w C:\WINDOWS\BricoPacks\SysFiles\77_netplwiz.dll
+ 2004-08-05 19:00:00 1,723,904 ----a-w C:\WINDOWS\BricoPacks\SysFiles\78_netshell.dll
+ 2004-08-05 19:00:00 251,392 ----a-w C:\WINDOWS\BricoPacks\SysFiles\79_newdev.dll
+ 2004-08-05 19:00:00 1,050,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\8_comctl32.dll
+ 2004-08-05 19:00:00 145,920 ----a-w C:\WINDOWS\BricoPacks\SysFiles\80_ntshrui.dll
+ 2007-12-07 02:08:34 102,912 ----a-w C:\WINDOWS\BricoPacks\SysFiles\81_occache.dll
+ 2004-08-05 19:00:00 172,032 ----a-w C:\WINDOWS\BricoPacks\SysFiles\82_photowiz.dll
+ 2004-08-05 19:00:00 578,560 ----a-w C:\WINDOWS\BricoPacks\SysFiles\83_printui.dll
+ 2004-08-05 19:00:00 685,056 ----a-w C:\WINDOWS\BricoPacks\SysFiles\84_rasdlg.dll
+ 2004-08-05 19:00:00 61,952 ----a-w C:\WINDOWS\BricoPacks\SysFiles\85_remotepg.dll
+ 2004-08-05 19:00:00 55,296 ----a-w C:\WINDOWS\BricoPacks\SysFiles\86_sendmail.dll
+ 2004-08-05 19:00:00 1,003,520 ----a-w C:\WINDOWS\BricoPacks\SysFiles\87_setupapi.dll
+ 2004-08-05 19:00:00 142,336 ----a-w C:\WINDOWS\BricoPacks\SysFiles\88_sfc_os.dll
+ 2004-08-05 19:00:00 572,416 ----a-w C:\WINDOWS\BricoPacks\SysFiles\89_shdoclc.dll
+ 2007-01-04 14:02:16 1,498,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\90_shdocvw.dll
+ 2004-08-05 19:00:00 440,320 ----a-w C:\WINDOWS\BricoPacks\SysFiles\91_shimgvw.dll
+ 2007-01-04 14:02:17 474,624 ----a-w C:\WINDOWS\BricoPacks\SysFiles\92_SHLWAPI.DLL
+ 2004-08-05 19:00:00 726,590 ----a-w C:\WINDOWS\BricoPacks\SysFiles\93_srchui.dll
+ 2004-08-05 19:00:00 241,664 ----a-w C:\WINDOWS\BricoPacks\SysFiles\94_srrstr.dll
+ 2004-08-05 19:00:00 138,240 ----a-w C:\WINDOWS\BricoPacks\SysFiles\95_sti_ci.dll
+ 2004-08-05 19:00:00 122,368 ----a-w C:\WINDOWS\BricoPacks\SysFiles\96_stobject.dll
+ 2004-08-05 19:00:00 197,120 ----a-w C:\WINDOWS\BricoPacks\SysFiles\97_syncui.dll
+ 2004-08-05 19:00:00 1,005,056 ----a-w C:\WINDOWS\BricoPacks\SysFiles\98_syssetup.dll
+ 2004-08-05 19:00:00 87,040 ----a-w C:\WINDOWS\BricoPacks\SysFiles\99_tapiui.dll
+ 2008-03-29 13:57:34 219,648 ----a-w C:\WINDOWS\BricoPacks\SysFiles\Ux_uxtheme.dll
+ 2008-03-24 17:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.28\FP_AX_CAB_INSTALLER.exe
+ 2008-03-24 17:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.29\FP_AX_CAB_INSTALLER.exe
- 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2000-08-31 06:00:00 89,504 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 06:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
- 2005-05-27 06:22:01 10,752 ----a-w C:\WINDOWS\hh.exe
+ 2005-05-27 06:22:01 167,936 ----a-w C:\WINDOWS\Hh.exe
+ 2004-08-05 19:00:00 2,589 ----a-w C:\WINDOWS\I386\RUNW32.BAT
+ 2007-12-07 02:08:32 124,928 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll
+ 2007-12-19 22:53:23 347,136 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll
+ 2007-12-07 02:08:32 214,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll
+ 2007-12-07 02:08:32 133,120 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll
+ 2007-12-07 02:08:32 63,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll
+ 2007-12-06 11:02:31 70,656 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe
+ 2007-12-07 02:08:32 153,088 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll
+ 2007-12-07 02:08:32 1,470,464 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll
+ 2007-12-06 04:59:51 161,792 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll
+ 2007-12-07 02:08:32 383,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll
+ 2007-12-07 02:08:32 384,512 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll
+ 2007-12-07 02:08:33 6,066,176 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll
+ 2007-12-07 02:08:33 150,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll
+ 2007-12-07 02:08:33 267,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll
+ 2007-12-06 11:00:58 13,824 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe
+ 2007-12-06 11:03:16 3,110,400 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
+ 2007-12-07 02:08:33 27,648 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll
+ 2007-12-07 02:08:33 459,264 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll
+ 2007-12-07 02:08:33 52,224 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll
+ 2007-12-08 05:08:36 5,864,960 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll
+ 2007-12-07 02:08:34 478,208 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll
+ 2007-12-07 02:08:34 193,024 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll
+ 2007-12-07 02:08:34 671,232 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll
+ 2007-12-07 02:08:34 905,728 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll
+ 2008-01-11 05:36:55 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll
+ 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll
+ 2007-12-07 02:08:34 489,472 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll
+ 2007-12-07 02:08:34 1,643,520 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll
+ 2007-12-07 02:08:34 1,451,008 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll
+ 2007-12-07 02:08:34 2,050,560 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
+ 2008-05-13 08:25:16 32,768 ----a-r C:\WINDOWS\Installer\{716E0306-8318-4364-8B8F-0CC4E9376BAC}\icon.exe
+ 2008-04-25 08:35:21 65,536 ----a-r C:\WINDOWS\Installer\{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}\ARPPRODUCTICON.exe
+ 2008-05-15 01:01:20 2,560 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2008-03-12 10:42:05 34,304 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2008-05-15 01:01:20 34,304 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2008-03-12 10:42:05 8,192 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2008-05-15 01:01:20 8,192 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-03-12 10:42:05 3,584 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2008-05-15 01:01:20 3,584 ----a-r C:\WINDOWS\Installer\{9019040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2008-03-12 10:42:05 16,384 ----a-r
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
29 mai 2008 à 18:20
29 mai 2008 à 18:20
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:17, on 2008-05-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Connect\mswmcls.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\DNA\btdna.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:\WINDOWS\system32\nnnLcCVl.dll (file missing)
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:\WINDOWS\system32\wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C484A5A1-5112-4DA6-AB3F-D4C05E8758D5} - C:\WINDOWS\system32\opnnliJy.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\eMule\Incoming\Common\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\RunServices: [MSys32] "C:\Program Files\Tetris 3000\data\morfitwebentrance.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [AlertEmail] C:\Program Files\AlertEmail\alertemail.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:\Program Files\LClock\LClock.exe
O4 - Startup: ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:\Program Files\UBISOFT\Prince of Persia l'Ame du Guerrier\Support\Register\RegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:\Program Files\UberIcon\UberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:\Program Files\3Deep Space\3D Solar System Screensaver\unins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5298/mcfscan.cab
O20 - Winlogon Notify: cbXQJaxW - C:\WINDOWS\
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: tuvUOEWO - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
Scan saved at 18:17, on 2008-05-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Connect\mswmcls.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\DNA\btdna.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:\WINDOWS\system32\nnnLcCVl.dll (file missing)
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:\WINDOWS\system32\wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C484A5A1-5112-4DA6-AB3F-D4C05E8758D5} - C:\WINDOWS\system32\opnnliJy.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\eMule\Incoming\Common\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\RunServices: [MSys32] "C:\Program Files\Tetris 3000\data\morfitwebentrance.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [AlertEmail] C:\Program Files\AlertEmail\alertemail.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:\Program Files\LClock\LClock.exe
O4 - Startup: ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:\Program Files\UBISOFT\Prince of Persia l'Ame du Guerrier\Support\Register\RegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:\Program Files\UberIcon\UberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:\Program Files\3Deep Space\3D Solar System Screensaver\unins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5298/mcfscan.cab
O20 - Winlogon Notify: cbXQJaxW - C:\WINDOWS\
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: tuvUOEWO - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
g!rly
Messages postés
18209
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
406
29 mai 2008 à 18:48
29 mai 2008 à 18:48
re,
verdict = tu etais/es tres infecté...
en plus le rapport combofix n´est pas complet...
passe ceci stp
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
Déroule la liste des instructions ci-dessous :
• Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum,
puis il me faut egalement le rapport de ceci :
Télécharge ComboScan sur ton Bureau en bas de cette pae en clickant sur download file
-> http://www.geekstogo.com/forum/files/
Ferme toutes les applications en cours : antivirus, pare-feu, etc ..
Double-clic sur comboscan.exe, dans la fenêtre qui s'affiche, clic sur OK.
Soit patient...
Le rapport Comboscan.txt s'affichera, copie et colle le contenu de ce fichier ici.
Le rapport peut-être long et en deux morceaux vérifie qu'il soit en entier.
@+
verdict = tu etais/es tres infecté...
en plus le rapport combofix n´est pas complet...
passe ceci stp
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
Déroule la liste des instructions ci-dessous :
• Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum,
puis il me faut egalement le rapport de ceci :
Télécharge ComboScan sur ton Bureau en bas de cette pae en clickant sur download file
-> http://www.geekstogo.com/forum/files/
Ferme toutes les applications en cours : antivirus, pare-feu, etc ..
Double-clic sur comboscan.exe, dans la fenêtre qui s'affiche, clic sur OK.
Soit patient...
Le rapport Comboscan.txt s'affichera, copie et colle le contenu de ce fichier ici.
Le rapport peut-être long et en deux morceaux vérifie qu'il soit en entier.
@+
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
30 mai 2008 à 10:35
30 mai 2008 à 10:35
voici bu boulot en perspective :)
JE vais m'y mettre ..
@+ pour le rapport et encore merci ;)
JE vais m'y mettre ..
@+ pour le rapport et encore merci ;)
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
30 mai 2008 à 13:38
30 mai 2008 à 13:38
voici ce que tu m'as demandé : attention roman en perspective :)
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Édition familiale (build 2600) SP 2.0
Architecture: X86; Language: French
CPU 0: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
CPU 1: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
Percentage of Memory in Use: 44%
Physical Memory (total/avail): 1013.4 MiB / 562.35 MiB
Pagefile Memory (total/avail): 2439.69 MiB / 2069.57 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1900.53 MiB
C: is Fixed (NTFS) - 228.64 GiB total, 138.64 GiB free.
D: is CDROM (No Media)
E: is Removable (FAT)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
J: is CDROM (CDFS)
\\.\PHYSICALDRIVE0 - SAMSUNG SP2504C - 232.88 GiB - 2 partitions
\PARTITION0 (bootable) - Système de fichiers installable - 228.64 GiB - C:
\PARTITION1 - Unknown - 4.24 GiB
\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device - 117.66 MiB - 1 partition
\PARTITION0 (bootable) - MS-DOS V4 Huge - 121.23 MiB - E:
\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
AV: PC Tools AntiVirus 4.0.0.26 v4.0.0.26 (PC Tools Research Pty Ltd) [COLOR=RED]Disabled/COLOR
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:btdna"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\WINDOWS\\system32\\javaw.exe"="C:\\WINDOWS\\system32\\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\laurent\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Fichiers communs
COMPUTERNAME=CHEZMOI
ComSpec=C:\WINDOWS\system32\cmd.exe
DEFAULT_CA_NR=CA6
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\laurent
LOGONSERVER=\\CHEZMOI
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\Microsoft SQL Server\80\Tools\Binn
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 6, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f06
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\laurent\LOCALS~1\Temp
TMP=C:\DOCUME~1\laurent\LOCALS~1\Temp
USERDOMAIN=CHEZMOI
USERNAME=laurent
USERPROFILE=C:\Documents and Settings\laurent
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
-- User Profiles ---------------------------------------------------------------
laurent [I](admin)/I
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\PC Tools AntiVirus\unins000.exe /LOG
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
ACDSee Pro 2 --> MsiExec.exe /I{4AAC95F4-A30E-4EE5-A086-6F79581D0D70}
Act 3d Silex Screensaver --> C:\Program Files\Act 3d\Silex Screensaver\uninstall.exe
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe BridgeTalk Plugin CS3 --> MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings --> C:\Program Files\Fichiers communs\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
Adobe Color Common Settings --> MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
Adobe Color EU Recommended Settings --> MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Extra Settings --> MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
Adobe Creative Suite 3 Web Premium --> MsiExec.exe /I{69B6B4A5-1C4D-4F16-BB11-A4EB9A439116}
Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2 --> C:\Program Files\Fichiers communs\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
Adobe Extension Manager CS3 --> MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
Adobe Flash CS3 --> MsiExec.exe /I{80FD3971-8482-49C8-BA8C-B6464A15882F}
Adobe Flash Player 9 ActiveX --> MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
Adobe Flash Player 9 Plugin --> MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Video Encoder --> MsiExec.exe /I{1B0BCA28-1F11-4D60-8A2F-DEBE04B5341E}
Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3 --> MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator CS3 --> MsiExec.exe /I{6E08CE13-C2AB-4749-9335-5900B958929E}
Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe MotionPicture Color Files --> MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3 --> MsiExec.exe /I{C1FA4B3B-1625-4922-9C9D-780E8FCE161A}
Adobe Reader 8.1.2 - Français --> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
Adobe Setup --> MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
Adobe Setup --> MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
Adobe Setup --> MsiExec.exe /I{BE136F60-5D0F-4663-8B32-938A3EFD3FCB}
Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WAS CS3 --> MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3 --> MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AHV content for Acrobat and Flash --> MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
Ajouter ou supprimer Adobe Creative Suite 3 Web Premium --> C:\Program Files\Fichiers communs\Adobe\Installers\e7f691c6f2bf7b70c25ea19f3d73b6e\Setup.exe
Archiveur WinRAR --> C:\Program Files\WinRAR\uninstall.exe
AudioConvert --> C:\PROGRA~1\AUDIOC~1\UNWISE.EXE C:\PROGRA~1\AUDIOC~1\INSTALL.LOG
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Barre d'outils Outlook de Windows Live (Windows Live Toolbar) --> MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
BitTorrent --> C:\Program Files\BitTorrent\uninst.exe
Bloqueur de fenêtres pop-up (Windows Live Toolbar) --> MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
CDBurnerXP --> "C:\Program Files\CDBurnerXP\unins000.exe"
CloneDVD2 --> "C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
Combined Community Codec Pack 2008-01-24 --> "C:\Program Files\Combined Community Codec Pack\unins000.exe"
CoreVorbis Audio Decoder (remove only) --> "C:\WINDOWS\system32\CoreVorbis-uninstall.exe"
Correctif pour Lecteur Windows Media 11 (KB939683) --> "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB914440) --> "C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
Correctif Windows XP - KB873333 --> C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
Correctif Windows XP - KB873339 --> C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Correctif Windows XP - KB885250 --> C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
Correctif Windows XP - KB885835 --> C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Correctif Windows XP - KB885836 --> C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Correctif Windows XP - KB885884 --> C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
Correctif Windows XP - KB886185 --> C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Correctif Windows XP - KB887472 --> C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Correctif Windows XP - KB887742 --> C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
Correctif Windows XP - KB887797 --> C:\WINDOWS\$NtUninstallKB887797$\spuninst\spuninst.exe
Correctif Windows XP - KB888113 --> C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
Correctif Windows XP - KB888302 --> C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Correctif Windows XP - KB890175 --> C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
Correctif Windows XP - KB890859 --> "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Correctif Windows XP - KB891781 --> C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Correctif Windows XP - KB893086 --> "C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
Cryptext (Remove Only) --> rundll32 setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\system32\ShellExt\Cryptext.inf
CursorXP --> C:\Program Files\CursorXP\CurXPUtil.exe -u
DAEMON Tools --> MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
Direct Show Ogg Vorbis Filter (remove only) --> "C:\WINDOWS\system32\OggDSuninst.exe"
Disc2Phone --> MsiExec.exe /I{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DNA --> "C:\Program Files\DNA\btdna.exe" /UNINSTALL
Détecteur de flux Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
DVD Region+CSS Free 5.9.1.0 --> "C:\Program Files\DVD Region+CSS Free\unins000.exe"
eMule --> "C:\Program Files\eMule\Uninstall.exe"
eMule Shell Extension --> MsiExec.exe /I{F1A2577D-2FDF-47D5-9055-ABE809D78D15}
EPSON Attach To Email --> C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Copy Utility 3 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
EPSON Easy Photo Print --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}\SETUP.EXE" -l0x40c UNINST
EPSON File Manager --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
EPSON Logiciel imprimante --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON PhotoQuicker3.5 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{65F5B7AF-3363-11D7-BB6B-00018021113F}\SETUP.EXE" -l0x9 uninst
EPSON PRINT Image Framer Tool2.0 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7BA1FB62-A363-4D24-8870-45131F0D0137}\Setup.exe" -l0x9 anything
EPSON Scan --> C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON Scan Assistant --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
EPSON Web-To-Page --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
ESDX5000_CX4900 Guide d’utilisation --> C:\Program Files\EPSON\TPMANUAL\ESDX5000_CX4900\USE_G\DOCUNINS.EXE
Extension de Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
ffdshow (remove only) --> "C:\Program Files\Combined Community Codec Pack\Filters\uninstall.exe"
Galerie de photos Windows Live --> MsiExec.exe /X{A70FA218-6598-4AC9-813D-63597C5DD068}
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB902344) --> "C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
iColorFolder --> C:\Program Files\iColorFolder\uninstall.exe
InCD --> C:\WINDOWS\NuNInst.exe /UNINSTALL
Intel(R) Graphics Media Accelerator Driver --> C:\WINDOWS\system32\igxpun.exe -uninstall
Intel(R) PRO Network Connections Drivers --> Prounstl.exe
IZArc 3.4.1.6 --> "C:\Program Files\IZArc\unins000.exe"
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Jewel Quest Solitaire --> "C:\Program Files\Jewel Quest Solitaire\ReflexiveArcade\unins000.exe"
Kaspersky Online Scanner --> C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
KC Softwares PhotoToFilm --> "C:\Program Files\KC Softwares\PhotoToFilm\unins000.exe"
Kyodai Mahjongg --> "C:\Program Files\Kyodai Mahjongg\unins000.exe"
Lame ACM MP3 Codec --> C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Menus intelligents (Windows Live Toolbar) --> MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
Microsoft ActiveSync 3.8 --> "C:\WINDOWS\ISUN040C.EXE" -f"C:\Program Files\Microsoft ActiveSync\DeIsL1.isu" -c"C:\Program Files\Microsoft ActiveSync\ceuninst.dll"
Microsoft Carioca --> MsiExec.exe /I{49D70E70-23CB-4BE5-8A67-8770F6B1BB2F}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office PowerPoint 2003 Template Pack 1 --> MsiExec.exe /I{90AB040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office PowerPoint 2003 Template Pack 3 --> MsiExec.exe /I{90AD040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office XP Professional avec FrontPage --> MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Microsoft Publisher 2002 --> MsiExec.exe /I{9019040C-6000-11D3-8CFE-0050048383C9}
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU] --> MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server Desktop Engine --> MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Lecteur Windows Media (KB911564) --> "C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734) --> "C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782) --> "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398) --> "C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB883939) --> "C:\WINDOWS\$NtUninstallKB883939$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB890046) --> "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB893066) --> "C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB893756) --> "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896358) --> "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896422) --> "C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896423) --> "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896424) --> "C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896428) --> "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB899587) --> "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB899591) --> "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB900725) --> "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB901017) --> "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB901214) --> "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB902400) --> "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB904706) --> "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB905414) --> "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB905749) --> "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB908519) --> "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB911562) --> "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB911927) --> "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB912919) --> "C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB913580) --> "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB914388) --> "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB914389) --> "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917344) --> "C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917422) --> "C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917953) --> "C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB918118) --> "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB918439) --> "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB919007) --> "C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920213) --> "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920670) --> "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920683) --> "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920685) --> "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB921503) --> "C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB922819) --> "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923191) --> "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923414) --> "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923689) --> "C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923694) --> "C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923980) --> "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924191) --> "C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924270) --> "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924496) --> "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924667) --> "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB925902) --> "C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB926255) --> "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB926436) --> "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB927779) --> "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB927802) --> "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928090) --> "C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928255) --> "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928843) --> "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB929123) --> "C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB930178) --> "C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB931261) --> "C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB931784) --> "C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB932168) --> "C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB933729) --> "C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB935839) --> "C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB935840) --> "C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB936021) --> "C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938829) --> "C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941202) --> "C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941568) --> "C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569) --> "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941644) --> "C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941693) --> "C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943055) --> "C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943460) --> "C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943485) --> "C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB944653) --> "C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB945553) --> "C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946026) --> "C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB948590) --> "C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB948881) --> "C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950749) --> "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB894391) --> "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB898461) --> "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB900485) --> "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB904942) --> "C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB908531) --> "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB910437) --> "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB911280) --> "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB916595) --> "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB920342) --> "C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB920872) --> "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB922582) --> "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB925720) --> "C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB925876) --> "C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB927891) --> "C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB929338) --> "C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB930916) --> "C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB931836) --> "C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB932823-v3) --> "C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB933360) --> "C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB936357) --> "C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB938828) --> "C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB942763) --> "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Nero Digital --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
Nero Media Player --> C:\WINDOWS\UNNMP.exe /UNINSTALL
Netlog 24 --> C:\WINDOWS\system32\Netlog24Uninstaller.exe
Neuf - Kit de connexion --> C:\Program Files\Neuf\Kit\uninstall.exe
OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{6D7F8D4B-D1A4-402A-973E-31E90940E585}
Outil de mise à jour Google --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Pack Gant3 oCeAn ShellPack 1.1 --> C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Remove.exe
Package de base Microsoft de service de chiffrement pour cartes à puce --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
PC Tools AntiVirus4.0 --> "C:\Program Files\PC Tools AntiVirus\unins000.exe"
PDF Settings --> MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Photo Tool --> C:\WINDOWS\system32\Uninstall Netlog Photo Tool.exe
PIF DESIGNER --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x40c anything
QuickTime --> MsiExec.exe /I{08094E03-AFE4-4853-9D31-6D0743DF5328}
RealPlayer --> C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
SigmaTel Audio --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x40c -remove -removeonly
Sony Ericsson PC Suite 1.20.224 --> MsiExec.exe /I{7689CA7A-1270-425A-9959-EB4CB25EA29A}
Spelling Dictionaries Support For Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
Sunplus Spca536 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73590C42-483E-421C-A394-CF153D4AD7B4}\setup.exe"
Totem Quest --> "C:\Program Files\Totem Quest\ReflexiveArcade\unins000.exe"
TV sur PC --> C:\Program Files\Neuf\TV_PC\uninstall.exe
USB Storage Driver --> DelUIDrv.exe
ViaMichelin Navigation PND --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47FF921C-E834-47A6-8CE4-F0A99CDE347F}\setup.exe" -l0x40c
Video Convert Master Trial Version (English) 7.9.0.5 --> "C:\Program Files\Video Convert Master\unins000.exe"
Windows Desktop Search 3.01 --> "C:\WINDOWS\$NtUninstallKB917013$\spuninst\spuninst.exe"
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Favorites pour Windows Live Toolbar --> MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live installer --> MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Mail --> MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
Windows Live Messenger --> MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Live Sign-in Assistant --> MsiExec.exe /I{0ED47137-C071-46CC-A243-E5E33271E10E}
Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
Windows Live Toolbar --> MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
Windows Live Writer --> MsiExec.exe /X{3DFF4274-EBB0-4356-9692-972965018954}
Windows Media Connect --> msiexec.exe /I {F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
Windows Media Connect --> MsiExec.exe /I{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Presentation Foundation Language Pack (FRA) --> MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
Windows Workflow Foundation FR Language Pack --> MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
XML Paper Specification Shared Components Language Pack 1.0 --> "C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
XML Paper Specification Shared Components Pack 1.0 -->
-- Application Event Log -------------------------------------------------------
Event Record #/Type11223 / Error
Event Submitted/Written: 05/29/2008 02:54:44 PM
Event ID/Source: 1000 / Application Error
Event Description:
Application défaillante divx player.exe, version 6.7.0.22, module défaillant splitter.ax, version 1.7.401.3, adresse de défaillance 0x00001b2c.
Traitement de l'événement propre au support pour [divx player.exe!ws!]
Event Record #/Type11195 / Error
Event Submitted/Written: 05/28/2008 02:26:36 PM
Event ID/Source: 1000 / Application Error
Event Description:
Application défaillante jqsolitaire.exe, version 1.0.0.1, module défaillant jqsolitaire.exe, version 1.0.0.1, adresse de défaillance 0x00023ca0.
Traitement de l'événement propre au support pour [jqsolitaire.exe!ws!]
Event Record #/Type11158 / Error
Event Submitted/Written: 05/27/2008 09:00:45 PM
Event ID/Source: 2001 / Microsoft Office 10
Event Description:
Rejected Safe Mode action : Microsoft PowerPoint.
Event Record #/Type11157 / Error
Event Submitted/Written: 05/27/2008 09:00:37 PM
Event ID/Source: 1000 / Microsoft Office 10
Event Description:
Faulting application powerpnt.exe, version 10.0.6819.0, faulting module mso.dll, version 10.0.6839.0, fault address 0x00003006.
Event Record #/Type11144 / Error
Event Submitted/Written: 05/27/2008 10:15:42 AM
Event ID/Source: 1000 / Windows Live Mail
Event Description:
wlmail.exe12.0.1606.1023471e44f8uxcore.dll12.0.1606.1023471e445f000037405
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type46462 / Error
Event Submitted/Written: 05/30/2008 11:00:56 AM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Le service Service Partage réseau du Lecteur Windows Media dépend du service Hôte de périphérique universel Plug-and-Play qui n'a pas pu démarrer en raison de l'erreur :
%%0
Event Record #/Type46450 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Le service Service Partage réseau du Lecteur Windows Media dépend du service Hôte de périphérique universel Plug-and-Play qui n'a pas pu démarrer en raison de l'erreur :
%%0
Event Record #/Type46449 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Le service PfModNT n'a pas pu démarrer en raison de l'erreur :
%%2
Event Record #/Type46448 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
Le service Accès du périphérique d'interface utilisateur s'est arrêté avec l'erreur :
%%126
Event Record #/Type46447 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Le service NMSAccess n'a pas pu démarrer en raison de l'erreur :
%%2
-- End of Deckard's System Scanner: finished at 2008-05-30 11:04:44 ------------
Deckard's System Scanner v20071014.68
Run by laurent on 2008-05-30 11:02:38
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
132: 2008-05-30 09:02:47 UTC - RP534 - Deckard's System Scanner Restore Point
131: 2008-05-29 15:46:57 UTC - RP533 - ComboFix created restore point
130: 2008-05-29 11:25:30 UTC - RP532 - Supprimé Worms 3D
129: 2008-05-28 15:59:45 UTC - RP531 - Last known good configuration
128: 2008-05-28 15:59:37 UTC - RP530 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-05-28 15:59:25 UTC - RP403 - Software Distribution Service 3.0
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as sabine.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:03, on 2008-05-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Connect\mswmcls.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\DNA\btdna.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\laurent\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\laurent.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:\WINDOWS\system32\nnnLcCVl.dll (file missing)
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:\WINDOWS\system32\wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C484A5A1-5112-4DA6-AB3F-D4C05E8758D5} - C:\WINDOWS\system32\opnnliJy.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\eMule\Incoming\Common\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\RunServices: [MSys32] "C:\Program Files\Tetris 3000\data\morfitwebentrance.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [AlertEmail] C:\Program Files\AlertEmail\alertemail.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:\Program Files\LClock\LClock.exe
O4 - Startup: ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:\Program Files\UBISOFT\Prince of Persia l'Ame du Guerrier\Support\Register\RegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:\Program Files\UberIcon\UberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:\Program Files\3Deep Space\3D Solar System Screensaver\unins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5298/mcfscan.cab
O20 - Winlogon Notify: cbXQJaxW - C:\WINDOWS\
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: tuvUOEWO - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Édition familiale (build 2600) SP 2.0
Architecture: X86; Language: French
CPU 0: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
CPU 1: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
Percentage of Memory in Use: 44%
Physical Memory (total/avail): 1013.4 MiB / 562.35 MiB
Pagefile Memory (total/avail): 2439.69 MiB / 2069.57 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1900.53 MiB
C: is Fixed (NTFS) - 228.64 GiB total, 138.64 GiB free.
D: is CDROM (No Media)
E: is Removable (FAT)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
J: is CDROM (CDFS)
\\.\PHYSICALDRIVE0 - SAMSUNG SP2504C - 232.88 GiB - 2 partitions
\PARTITION0 (bootable) - Système de fichiers installable - 228.64 GiB - C:
\PARTITION1 - Unknown - 4.24 GiB
\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device - 117.66 MiB - 1 partition
\PARTITION0 (bootable) - MS-DOS V4 Huge - 121.23 MiB - E:
\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
AV: PC Tools AntiVirus 4.0.0.26 v4.0.0.26 (PC Tools Research Pty Ltd) [COLOR=RED]Disabled/COLOR
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:btdna"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\WINDOWS\\system32\\javaw.exe"="C:\\WINDOWS\\system32\\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\laurent\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Fichiers communs
COMPUTERNAME=CHEZMOI
ComSpec=C:\WINDOWS\system32\cmd.exe
DEFAULT_CA_NR=CA6
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\laurent
LOGONSERVER=\\CHEZMOI
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\Microsoft SQL Server\80\Tools\Binn
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 6, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f06
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\laurent\LOCALS~1\Temp
TMP=C:\DOCUME~1\laurent\LOCALS~1\Temp
USERDOMAIN=CHEZMOI
USERNAME=laurent
USERPROFILE=C:\Documents and Settings\laurent
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
-- User Profiles ---------------------------------------------------------------
laurent [I](admin)/I
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\PC Tools AntiVirus\unins000.exe /LOG
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
ACDSee Pro 2 --> MsiExec.exe /I{4AAC95F4-A30E-4EE5-A086-6F79581D0D70}
Act 3d Silex Screensaver --> C:\Program Files\Act 3d\Silex Screensaver\uninstall.exe
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe BridgeTalk Plugin CS3 --> MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings --> C:\Program Files\Fichiers communs\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
Adobe Color Common Settings --> MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
Adobe Color EU Recommended Settings --> MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Extra Settings --> MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
Adobe Creative Suite 3 Web Premium --> MsiExec.exe /I{69B6B4A5-1C4D-4F16-BB11-A4EB9A439116}
Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2 --> C:\Program Files\Fichiers communs\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
Adobe Extension Manager CS3 --> MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
Adobe Flash CS3 --> MsiExec.exe /I{80FD3971-8482-49C8-BA8C-B6464A15882F}
Adobe Flash Player 9 ActiveX --> MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
Adobe Flash Player 9 Plugin --> MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Video Encoder --> MsiExec.exe /I{1B0BCA28-1F11-4D60-8A2F-DEBE04B5341E}
Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3 --> MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator CS3 --> MsiExec.exe /I{6E08CE13-C2AB-4749-9335-5900B958929E}
Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe MotionPicture Color Files --> MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3 --> MsiExec.exe /I{C1FA4B3B-1625-4922-9C9D-780E8FCE161A}
Adobe Reader 8.1.2 - Français --> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
Adobe Setup --> MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
Adobe Setup --> MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
Adobe Setup --> MsiExec.exe /I{BE136F60-5D0F-4663-8B32-938A3EFD3FCB}
Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WAS CS3 --> MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3 --> MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
AHV content for Acrobat and Flash --> MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
Ajouter ou supprimer Adobe Creative Suite 3 Web Premium --> C:\Program Files\Fichiers communs\Adobe\Installers\e7f691c6f2bf7b70c25ea19f3d73b6e\Setup.exe
Archiveur WinRAR --> C:\Program Files\WinRAR\uninstall.exe
AudioConvert --> C:\PROGRA~1\AUDIOC~1\UNWISE.EXE C:\PROGRA~1\AUDIOC~1\INSTALL.LOG
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Barre d'outils Outlook de Windows Live (Windows Live Toolbar) --> MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
BitTorrent --> C:\Program Files\BitTorrent\uninst.exe
Bloqueur de fenêtres pop-up (Windows Live Toolbar) --> MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
CDBurnerXP --> "C:\Program Files\CDBurnerXP\unins000.exe"
CloneDVD2 --> "C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
Combined Community Codec Pack 2008-01-24 --> "C:\Program Files\Combined Community Codec Pack\unins000.exe"
CoreVorbis Audio Decoder (remove only) --> "C:\WINDOWS\system32\CoreVorbis-uninstall.exe"
Correctif pour Lecteur Windows Media 11 (KB939683) --> "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB914440) --> "C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
Correctif Windows XP - KB873333 --> C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
Correctif Windows XP - KB873339 --> C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Correctif Windows XP - KB885250 --> C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
Correctif Windows XP - KB885835 --> C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Correctif Windows XP - KB885836 --> C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Correctif Windows XP - KB885884 --> C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
Correctif Windows XP - KB886185 --> C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Correctif Windows XP - KB887472 --> C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Correctif Windows XP - KB887742 --> C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
Correctif Windows XP - KB887797 --> C:\WINDOWS\$NtUninstallKB887797$\spuninst\spuninst.exe
Correctif Windows XP - KB888113 --> C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
Correctif Windows XP - KB888302 --> C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Correctif Windows XP - KB890175 --> C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
Correctif Windows XP - KB890859 --> "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Correctif Windows XP - KB891781 --> C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Correctif Windows XP - KB893086 --> "C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
Cryptext (Remove Only) --> rundll32 setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\system32\ShellExt\Cryptext.inf
CursorXP --> C:\Program Files\CursorXP\CurXPUtil.exe -u
DAEMON Tools --> MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
Direct Show Ogg Vorbis Filter (remove only) --> "C:\WINDOWS\system32\OggDSuninst.exe"
Disc2Phone --> MsiExec.exe /I{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DNA --> "C:\Program Files\DNA\btdna.exe" /UNINSTALL
Détecteur de flux Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
DVD Region+CSS Free 5.9.1.0 --> "C:\Program Files\DVD Region+CSS Free\unins000.exe"
eMule --> "C:\Program Files\eMule\Uninstall.exe"
eMule Shell Extension --> MsiExec.exe /I{F1A2577D-2FDF-47D5-9055-ABE809D78D15}
EPSON Attach To Email --> C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Copy Utility 3 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
EPSON Easy Photo Print --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}\SETUP.EXE" -l0x40c UNINST
EPSON File Manager --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
EPSON Logiciel imprimante --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON PhotoQuicker3.5 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{65F5B7AF-3363-11D7-BB6B-00018021113F}\SETUP.EXE" -l0x9 uninst
EPSON PRINT Image Framer Tool2.0 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7BA1FB62-A363-4D24-8870-45131F0D0137}\Setup.exe" -l0x9 anything
EPSON Scan --> C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON Scan Assistant --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
EPSON Web-To-Page --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
ESDX5000_CX4900 Guide d’utilisation --> C:\Program Files\EPSON\TPMANUAL\ESDX5000_CX4900\USE_G\DOCUNINS.EXE
Extension de Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
ffdshow (remove only) --> "C:\Program Files\Combined Community Codec Pack\Filters\uninstall.exe"
Galerie de photos Windows Live --> MsiExec.exe /X{A70FA218-6598-4AC9-813D-63597C5DD068}
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB902344) --> "C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
iColorFolder --> C:\Program Files\iColorFolder\uninstall.exe
InCD --> C:\WINDOWS\NuNInst.exe /UNINSTALL
Intel(R) Graphics Media Accelerator Driver --> C:\WINDOWS\system32\igxpun.exe -uninstall
Intel(R) PRO Network Connections Drivers --> Prounstl.exe
IZArc 3.4.1.6 --> "C:\Program Files\IZArc\unins000.exe"
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Jewel Quest Solitaire --> "C:\Program Files\Jewel Quest Solitaire\ReflexiveArcade\unins000.exe"
Kaspersky Online Scanner --> C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
KC Softwares PhotoToFilm --> "C:\Program Files\KC Softwares\PhotoToFilm\unins000.exe"
Kyodai Mahjongg --> "C:\Program Files\Kyodai Mahjongg\unins000.exe"
Lame ACM MP3 Codec --> C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Menus intelligents (Windows Live Toolbar) --> MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
Microsoft ActiveSync 3.8 --> "C:\WINDOWS\ISUN040C.EXE" -f"C:\Program Files\Microsoft ActiveSync\DeIsL1.isu" -c"C:\Program Files\Microsoft ActiveSync\ceuninst.dll"
Microsoft Carioca --> MsiExec.exe /I{49D70E70-23CB-4BE5-8A67-8770F6B1BB2F}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office PowerPoint 2003 Template Pack 1 --> MsiExec.exe /I{90AB040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office PowerPoint 2003 Template Pack 3 --> MsiExec.exe /I{90AD040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office XP Professional avec FrontPage --> MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Microsoft Publisher 2002 --> MsiExec.exe /I{9019040C-6000-11D3-8CFE-0050048383C9}
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU] --> MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server Desktop Engine --> MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mise à jour de sécurité pour Lecteur Windows Media (KB911564) --> "C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734) --> "C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782) --> "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398) --> "C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB883939) --> "C:\WINDOWS\$NtUninstallKB883939$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB890046) --> "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB893066) --> "C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB893756) --> "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896358) --> "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896422) --> "C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896423) --> "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896424) --> "C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB896428) --> "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB899587) --> "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB899591) --> "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB900725) --> "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB901017) --> "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB901214) --> "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB902400) --> "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB904706) --> "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB905414) --> "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB905749) --> "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB908519) --> "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB911562) --> "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB911927) --> "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB912919) --> "C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB913580) --> "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB914388) --> "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB914389) --> "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917344) --> "C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917422) --> "C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB917953) --> "C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB918118) --> "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB918439) --> "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB919007) --> "C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920213) --> "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920670) --> "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920683) --> "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB920685) --> "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB921503) --> "C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB922819) --> "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923191) --> "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923414) --> "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923689) --> "C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923694) --> "C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923980) --> "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924191) --> "C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924270) --> "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924496) --> "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB924667) --> "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB925902) --> "C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB926255) --> "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB926436) --> "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB927779) --> "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB927802) --> "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928090) --> "C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928255) --> "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB928843) --> "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB929123) --> "C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB930178) --> "C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB931261) --> "C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB931784) --> "C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB932168) --> "C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB933729) --> "C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB935839) --> "C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB935840) --> "C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB936021) --> "C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938829) --> "C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941202) --> "C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941568) --> "C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569) --> "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941644) --> "C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941693) --> "C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943055) --> "C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943460) --> "C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB943485) --> "C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB944653) --> "C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB945553) --> "C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946026) --> "C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB948590) --> "C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB948881) --> "C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950749) --> "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB894391) --> "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB898461) --> "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB900485) --> "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB904942) --> "C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB908531) --> "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB910437) --> "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB911280) --> "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB916595) --> "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB920342) --> "C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB920872) --> "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB922582) --> "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB925720) --> "C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB925876) --> "C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB927891) --> "C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB929338) --> "C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB930916) --> "C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB931836) --> "C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB932823-v3) --> "C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB933360) --> "C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB936357) --> "C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB938828) --> "C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB942763) --> "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Nero Digital --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
Nero Media Player --> C:\WINDOWS\UNNMP.exe /UNINSTALL
Netlog 24 --> C:\WINDOWS\system32\Netlog24Uninstaller.exe
Neuf - Kit de connexion --> C:\Program Files\Neuf\Kit\uninstall.exe
OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{6D7F8D4B-D1A4-402A-973E-31E90940E585}
Outil de mise à jour Google --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Pack Gant3 oCeAn ShellPack 1.1 --> C:\WINDOWS\BricoPacks\Gant3 oCeAn ShellPack\Remove.exe
Package de base Microsoft de service de chiffrement pour cartes à puce --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
PC Tools AntiVirus4.0 --> "C:\Program Files\PC Tools AntiVirus\unins000.exe"
PDF Settings --> MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Photo Tool --> C:\WINDOWS\system32\Uninstall Netlog Photo Tool.exe
PIF DESIGNER --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x40c anything
QuickTime --> MsiExec.exe /I{08094E03-AFE4-4853-9D31-6D0743DF5328}
RealPlayer --> C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
SigmaTel Audio --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x40c -remove -removeonly
Sony Ericsson PC Suite 1.20.224 --> MsiExec.exe /I{7689CA7A-1270-425A-9959-EB4CB25EA29A}
Spelling Dictionaries Support For Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
Sunplus Spca536 --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73590C42-483E-421C-A394-CF153D4AD7B4}\setup.exe"
Totem Quest --> "C:\Program Files\Totem Quest\ReflexiveArcade\unins000.exe"
TV sur PC --> C:\Program Files\Neuf\TV_PC\uninstall.exe
USB Storage Driver --> DelUIDrv.exe
ViaMichelin Navigation PND --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47FF921C-E834-47A6-8CE4-F0A99CDE347F}\setup.exe" -l0x40c
Video Convert Master Trial Version (English) 7.9.0.5 --> "C:\Program Files\Video Convert Master\unins000.exe"
Windows Desktop Search 3.01 --> "C:\WINDOWS\$NtUninstallKB917013$\spuninst\spuninst.exe"
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Favorites pour Windows Live Toolbar --> MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live installer --> MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Mail --> MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
Windows Live Messenger --> MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Live Sign-in Assistant --> MsiExec.exe /I{0ED47137-C071-46CC-A243-E5E33271E10E}
Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
Windows Live Toolbar --> MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
Windows Live Writer --> MsiExec.exe /X{3DFF4274-EBB0-4356-9692-972965018954}
Windows Media Connect --> msiexec.exe /I {F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
Windows Media Connect --> MsiExec.exe /I{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Presentation Foundation Language Pack (FRA) --> MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
Windows Workflow Foundation FR Language Pack --> MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
XML Paper Specification Shared Components Language Pack 1.0 --> "C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
XML Paper Specification Shared Components Pack 1.0 -->
-- Application Event Log -------------------------------------------------------
Event Record #/Type11223 / Error
Event Submitted/Written: 05/29/2008 02:54:44 PM
Event ID/Source: 1000 / Application Error
Event Description:
Application défaillante divx player.exe, version 6.7.0.22, module défaillant splitter.ax, version 1.7.401.3, adresse de défaillance 0x00001b2c.
Traitement de l'événement propre au support pour [divx player.exe!ws!]
Event Record #/Type11195 / Error
Event Submitted/Written: 05/28/2008 02:26:36 PM
Event ID/Source: 1000 / Application Error
Event Description:
Application défaillante jqsolitaire.exe, version 1.0.0.1, module défaillant jqsolitaire.exe, version 1.0.0.1, adresse de défaillance 0x00023ca0.
Traitement de l'événement propre au support pour [jqsolitaire.exe!ws!]
Event Record #/Type11158 / Error
Event Submitted/Written: 05/27/2008 09:00:45 PM
Event ID/Source: 2001 / Microsoft Office 10
Event Description:
Rejected Safe Mode action : Microsoft PowerPoint.
Event Record #/Type11157 / Error
Event Submitted/Written: 05/27/2008 09:00:37 PM
Event ID/Source: 1000 / Microsoft Office 10
Event Description:
Faulting application powerpnt.exe, version 10.0.6819.0, faulting module mso.dll, version 10.0.6839.0, fault address 0x00003006.
Event Record #/Type11144 / Error
Event Submitted/Written: 05/27/2008 10:15:42 AM
Event ID/Source: 1000 / Windows Live Mail
Event Description:
wlmail.exe12.0.1606.1023471e44f8uxcore.dll12.0.1606.1023471e445f000037405
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type46462 / Error
Event Submitted/Written: 05/30/2008 11:00:56 AM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Le service Service Partage réseau du Lecteur Windows Media dépend du service Hôte de périphérique universel Plug-and-Play qui n'a pas pu démarrer en raison de l'erreur :
%%0
Event Record #/Type46450 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Le service Service Partage réseau du Lecteur Windows Media dépend du service Hôte de périphérique universel Plug-and-Play qui n'a pas pu démarrer en raison de l'erreur :
%%0
Event Record #/Type46449 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Le service PfModNT n'a pas pu démarrer en raison de l'erreur :
%%2
Event Record #/Type46448 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
Le service Accès du périphérique d'interface utilisateur s'est arrêté avec l'erreur :
%%126
Event Record #/Type46447 / Error
Event Submitted/Written: 05/30/2008 10:50:57 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Le service NMSAccess n'a pas pu démarrer en raison de l'erreur :
%%2
-- End of Deckard's System Scanner: finished at 2008-05-30 11:04:44 ------------
Deckard's System Scanner v20071014.68
Run by laurent on 2008-05-30 11:02:38
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
132: 2008-05-30 09:02:47 UTC - RP534 - Deckard's System Scanner Restore Point
131: 2008-05-29 15:46:57 UTC - RP533 - ComboFix created restore point
130: 2008-05-29 11:25:30 UTC - RP532 - Supprimé Worms 3D
129: 2008-05-28 15:59:45 UTC - RP531 - Last known good configuration
128: 2008-05-28 15:59:37 UTC - RP530 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-05-28 15:59:25 UTC - RP403 - Software Distribution Service 3.0
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as sabine.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:03, on 2008-05-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Connect\mswmcls.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\DNA\btdna.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\laurent\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\laurent.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:\WINDOWS\system32\nnnLcCVl.dll (file missing)
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:\WINDOWS\system32\wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C484A5A1-5112-4DA6-AB3F-D4C05E8758D5} - C:\WINDOWS\system32\opnnliJy.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\eMule\Incoming\Common\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\RunServices: [MSys32] "C:\Program Files\Tetris 3000\data\morfitwebentrance.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [AlertEmail] C:\Program Files\AlertEmail\alertemail.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:\Program Files\LClock\LClock.exe
O4 - Startup: ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:\Program Files\UBISOFT\Prince of Persia l'Ame du Guerrier\Support\Register\RegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:\Program Files\UberIcon\UberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:\Program Files\3Deep Space\3D Solar System Screensaver\unins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5298/mcfscan.cab
O20 - Winlogon Notify: cbXQJaxW - C:\WINDOWS\
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: tuvUOEWO - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
30 mai 2008 à 13:43
30 mai 2008 à 13:43
suite ...........
[b]SDFix: Version 1.187 [/b]
Run by laurent on 2008-05-30 at 10:45
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\laurent\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-30 10:54:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,de,55,1e,33,0f,73,a3,b8,7a,ae,fb,ed,50,cc,11,c1,3e,..
"hj34z0"=hex:4c,a0,7c,1d,c5,f2,ed,99,25,90,06,b5,aa,e3,73,15,4a,bd,bf,91,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:9d4280c5
"s2"=dword:6dda1377
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{004C2F16-B2BA-4739-BA3C-ADBBD8A71850}]
"faklnlalnhcd"=hex:66,61,65,62,6d,69,67,66,63,66,66,64,00,00
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:btdna"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\WINDOWS\\system32\\javaw.exe"="C:\\WINDOWS\\system32\\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
[b]Files with Hidden Attributes [/b]:
Fri 2 Nov 2007 56 ..SHR --- "C:\WINDOWS\system32\5C84FAE664.sys"
Fri 2 Nov 2007 1,682 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Wed 14 Feb 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 13 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 9 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT5.tmp"
Tue 13 Feb 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\53a3a14f74503141a8462ffdac5b76db\download\BIT9F.tmp"
Tue 13 Feb 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\c40c0e3d7dcfb5be7fb7777a31340af0\download\BIT96.tmp"
[b]Finished![/b]
et j'ajoute ça je sais plus si c'est nécessaire j'ai été mangé entre temps mdr
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-30 10:54:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,de,55,1e,33,0f,73,a3,b8,7a,ae,fb,ed,50,cc,11,c1,3e,..
"hj34z0"=hex:4c,a0,7c,1d,c5,f2,ed,99,25,90,06,b5,aa,e3,73,15,4a,bd,bf,91,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:9d4280c5
"s2"=dword:6dda1377
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{004C2F16-B2BA-4739-BA3C-ADBBD8A71850}]
"faklnlalnhcd"=hex:66,61,65,62,6d,69,67,66,63,66,66,64,00,00
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
voilà j'attends tes conclusions merci
Sympa la petite blagounette :) je n'en connais pas de soft dommage ....
[b]SDFix: Version 1.187 [/b]
Run by laurent on 2008-05-30 at 10:45
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\laurent\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-30 10:54:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,de,55,1e,33,0f,73,a3,b8,7a,ae,fb,ed,50,cc,11,c1,3e,..
"hj34z0"=hex:4c,a0,7c,1d,c5,f2,ed,99,25,90,06,b5,aa,e3,73,15,4a,bd,bf,91,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:9d4280c5
"s2"=dword:6dda1377
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{004C2F16-B2BA-4739-BA3C-ADBBD8A71850}]
"faklnlalnhcd"=hex:66,61,65,62,6d,69,67,66,63,66,66,64,00,00
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:btdna"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\WINDOWS\\system32\\javaw.exe"="C:\\WINDOWS\\system32\\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
[b]Files with Hidden Attributes [/b]:
Fri 2 Nov 2007 56 ..SHR --- "C:\WINDOWS\system32\5C84FAE664.sys"
Fri 2 Nov 2007 1,682 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Wed 14 Feb 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 13 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 9 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT5.tmp"
Tue 13 Feb 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\53a3a14f74503141a8462ffdac5b76db\download\BIT9F.tmp"
Tue 13 Feb 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\c40c0e3d7dcfb5be7fb7777a31340af0\download\BIT96.tmp"
[b]Finished![/b]
et j'ajoute ça je sais plus si c'est nécessaire j'ai été mangé entre temps mdr
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-30 10:54:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,de,55,1e,33,0f,73,a3,b8,7a,ae,fb,ed,50,cc,11,c1,3e,..
"hj34z0"=hex:4c,a0,7c,1d,c5,f2,ed,99,25,90,06,b5,aa,e3,73,15,4a,bd,bf,91,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:9d4280c5
"s2"=dword:6dda1377
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:8a,96,8b,3b,8a,67,e3,8d,e8,5d,a0,55,3a,65,ab,68,5a,c3,58,91,cb,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:a3,53,76,83,8f,f1,a4,13,53,46,19,3c,fc,39,5d,0b,6d,7e,a4,14,e3,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{004C2F16-B2BA-4739-BA3C-ADBBD8A71850}]
"faklnlalnhcd"=hex:66,61,65,62,6d,69,67,66,63,66,66,64,00,00
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
voilà j'attends tes conclusions merci
Sympa la petite blagounette :) je n'en connais pas de soft dommage ....
La solution, qui a tout arrangé pour moi :
Télécharger l'antivirus "Malwarebytes" (gratuit et en français !) et lui faire faire une analyse du système. Il m'a trouvé une soixantaine de fichiers infectés, alors que Norton (que j'ai payé !) m'expliquait que tout allait bien... Après la suppression de ces fichiers par l'antivirus, tout est rentré dans l'ordre, y compris les mises à jours automatiques.
Le problème avait un nom : "Trojan Vundo".
Télécharger l'antivirus "Malwarebytes" (gratuit et en français !) et lui faire faire une analyse du système. Il m'a trouvé une soixantaine de fichiers infectés, alors que Norton (que j'ai payé !) m'expliquait que tout allait bien... Après la suppression de ces fichiers par l'antivirus, tout est rentré dans l'ordre, y compris les mises à jours automatiques.
Le problème avait un nom : "Trojan Vundo".
higelin22
Messages postés
263
Date d'inscription
mardi 27 mai 2008
Statut
Membre
Dernière intervention
17 juin 2008
15
30 mai 2008 à 16:16
30 mai 2008 à 16:16
le probleme c'est que dans son rapport il n y a pas que le virus comme probleme
g!rly
Messages postés
18209
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
406
30 mai 2008 à 18:57
30 mai 2008 à 18:57
salut,
la suite :
supprime :
:\WINDOWS\system32\toliepgm.VIR000
C:\WINDOWS\system32\nnnLcCVl.VIR
Fais un scan avec cet antispyware :
Telecharge malwarebytes + tutoriel :
-> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
puis post un nouveau rapport hijack this stp
@+
la suite :
supprime :
:\WINDOWS\system32\toliepgm.VIR000
C:\WINDOWS\system32\nnnLcCVl.VIR
Fais un scan avec cet antispyware :
Telecharge malwarebytes + tutoriel :
-> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
puis post un nouveau rapport hijack this stp
@+
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
30 mai 2008 à 23:50
30 mai 2008 à 23:50
ok voici 1
Malwarebytes' Anti-Malware 1.14
Version de la base de données: 804
23:38:57 2008-05-30
mbam-log-5-30-2008 (23-38-57).txt
Type de recherche: Examen complet (C:\|D:\|E:\|F:\|H:\|J:\|M:\|)
Eléments examinés: 209606
Temps écoulé: 1 hour(s), 16 minute(s), 41 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\QooBox\Quarantine\C\WINDOWS\system32\hsvtotgd.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP523\A0128379.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP523\A0128380.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP524\A0128417.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP533\A0130115.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Program Files\RngInterstitial.dll (Rogue.MalwarePatrolPro) -> Quarantined and deleted successfully.
Puis le 2
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:44, on 2008-05-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Connect\mswmcls.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\DNA\btdna.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:\WINDOWS\system32\nnnLcCVl.dll (file missing)
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:\WINDOWS\system32\wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C484A5A1-5112-4DA6-AB3F-D4C05E8758D5} - C:\WINDOWS\system32\opnnliJy.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\eMule\Incoming\Common\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\RunServices: [MSys32] "C:\Program Files\Tetris 3000\data\morfitwebentrance.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [AlertEmail] C:\Program Files\AlertEmail\alertemail.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:\Program Files\LClock\LClock.exe
O4 - Startup: ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:\Program Files\UBISOFT\Prince of Persia l'Ame du Guerrier\Support\Register\RegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:\Program Files\UberIcon\UberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:\Program Files\3Deep Space\3D Solar System Screensaver\unins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5298/mcfscan.cab
O20 - Winlogon Notify: cbXQJaxW - C:\WINDOWS\
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: tuvUOEWO - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
Malwarebytes' Anti-Malware 1.14
Version de la base de données: 804
23:38:57 2008-05-30
mbam-log-5-30-2008 (23-38-57).txt
Type de recherche: Examen complet (C:\|D:\|E:\|F:\|H:\|J:\|M:\|)
Eléments examinés: 209606
Temps écoulé: 1 hour(s), 16 minute(s), 41 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 6
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\QooBox\Quarantine\C\WINDOWS\system32\hsvtotgd.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP523\A0128379.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP523\A0128380.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP524\A0128417.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{03498D5A-81CF-4588-B8F8-45516A70FB13}\RP533\A0130115.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Program Files\RngInterstitial.dll (Rogue.MalwarePatrolPro) -> Quarantined and deleted successfully.
Puis le 2
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:44, on 2008-05-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Connect\mswmcls.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\DNA\btdna.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4068CDAE-EEAA-4C96-8278-E6D3583E8E65} - C:\WINDOWS\system32\nnnLcCVl.dll (file missing)
O2 - BHO: (no name) - {66BB5494-08F1-47A6-B538-381B26B26D9F} - C:\WINDOWS\system32\wvUKDTKc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C484A5A1-5112-4DA6-AB3F-D4C05E8758D5} - C:\WINDOWS\system32\opnnliJy.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\eMule\Incoming\Common\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\RunServices: [MSys32] "C:\Program Files\Tetris 3000\data\morfitwebentrance.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [AlertEmail] C:\Program Files\AlertEmail\alertemail.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LClock.lnk = C:\Program Files\LClock\LClock.exe
O4 - Startup: ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Registration .LNK = ?
O4 - Startup: Registration Prince of Persia l'Ame du Guerrier.LNK = C:\Program Files\UBISOFT\Prince of Persia l'Ame du Guerrier\Support\Register\RegistrationReminder.exe
O4 - Startup: UberIcon.lnk = C:\Program Files\UberIcon\UberIcon Manager.exe
O4 - Startup: Uninstall 3D Solar System Screensaver.lnk = C:\Program Files\3Deep Space\3D Solar System Screensaver\unins000.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117w.bay117.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lyykane.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5298/mcfscan.cab
O20 - Winlogon Notify: cbXQJaxW - C:\WINDOWS\
O20 - Winlogon Notify: cnzzukdz - cnzzukdz.dll (file missing)
O20 - Winlogon Notify: hggddcy - hggddcy.dll (file missing)
O20 - Winlogon Notify: rqRJawXN - rqRJawXN.dll (file missing)
O20 - Winlogon Notify: tuvUOEWO - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
g!rly
Messages postés
18209
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
406
31 mai 2008 à 20:31
31 mai 2008 à 20:31
salut,
donc tu as fais un scan a l´aide de kaspersky ?!
fais ceci
Désactive ta restauration système:
pour cela :
Click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration système;
coche la case désactiver la restauration systèm et applique.
puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration systèm
décoche la case désactiver la restauration systèm et applique.
peux tu quand meme poster le rapport de kaspersky stp
@+
donc tu as fais un scan a l´aide de kaspersky ?!
fais ceci
Désactive ta restauration système:
pour cela :
Click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration système;
coche la case désactiver la restauration systèm et applique.
puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
dans la nouvelle fenettre click sur l´onglet restauration systèm
décoche la case désactiver la restauration systèm et applique.
peux tu quand meme poster le rapport de kaspersky stp
@+
lyykane
Messages postés
18
Date d'inscription
lundi 19 mai 2008
Statut
Membre
Dernière intervention
11 août 2010
8 juin 2008 à 11:51
8 juin 2008 à 11:51
salut bon je n'ai pas réussi à mettre tout ce que tu me demandes mais la bonne nouvellle c'est que je suis ravi de mon antivirus même s'il faut payer alors tant pis au moins je suis tranquille, virus et autre terminer. voilà mon ordi est propre :) merci à tous particulierement g!rly...
higelin22
Messages postés
263
Date d'inscription
mardi 27 mai 2008
Statut
Membre
Dernière intervention
17 juin 2008
15
9 juin 2008 à 15:07
9 juin 2008 à 15:07
..